Enterprise Security

Security & Compliance

How Legal Brain protects your firm's data, your clients' privacy, and your professional reputation.

90%
7 of 8 Domains Strong

Security Coverage by Domain

How well each security area is covered in Legal Brain

Data Privacy
95%
PII Protection
92%
Authentication
92%
Network Security
90%
Intrusion Detection
88%
AI/Prompt Security
82%
Encryption at Rest
90%

PII Anonymisation Flow

Step-by-step: how client data is protected before AI processing

Step 1
User submits query
Contains names, ABNs, addresses
Local
Step 2
PII detection engine
Comprehensive scanning
Local
Step 3
PII stripped & replaced
Identifying data removed
Local
Step 4
Anonymised query sent
HTTPS/TLS encrypted
Encrypted
Step 5
AI processes anonymised data
No PII visible to AI
API
Step 6
Response received
Contains tokens only
Encrypted
Step 7
Local de-anonymisation
Restores original names
Local
Step 8
Complete response
User sees real names
Local

Data Security Layers

Defence in depth: five concentric layers of protection

TLS/HTTPS
Encryption in Transit
CSRF Protection &
Rate Limiting
Secure Authentication
+ 2FA
Per-User
Data Isolation
PII
Anonymisation
Network & transport security
Application & data security

What Legal Brain Already Has

Security features implemented and ready for review

🔒 Data Privacy

  • Your data stays under your control at all times
  • No third-party cloud storage of your firm's information
  • Documents, chat history, and user data are fully protected

🚫 PII Anonymisation

  • Comprehensive automatic detection of personal information: names, emails, phones, ABNs, ACNs, TFNs, Medicare numbers, bank accounts, credit cards, DOBs, addresses
  • Context-aware detection of names, companies, and case parties
  • Legal citations preserved intact through the anonymisation process
  • PII mappings are ephemeral and never persisted

🔐 Authentication

  • Industry-standard password hashing
  • Protection against timing attacks and credential enumeration
  • CSRF protection on all forms
  • Cryptographically secure session management
  • Brute-force protection with automated lockout
  • Rate-limited password resets with expiring tokens
  • Support for time-limited user accounts

🌐 Network Security

  • End-to-end encryption with DDoS protection
  • Full suite of security headers (HSTS, CSP, X-Frame-Options, and more)
  • Strict content and permissions policies
  • Request size limits to prevent abuse
  • Server technology fingerprinting disabled

🚨 Intrusion Detection

  • Real-time scanning for common attack patterns (XSS, injection, traversal, and more)
  • Automated bot and vulnerability scanner detection
  • Honeypot traps for common attack vectors
  • Automated IP blocking for suspicious activity
  • Comprehensive security audit logging

🤖 AI / Prompt Security

  • Hardened system prompts that refuse architecture and internal detail requests
  • Multiple layers of prompt injection defence
  • Uploaded documents treated as untrusted input
  • Defence against jailbreak attempts including social engineering and encoded tricks
  • 10+ adversarial tests run; 80%+ pass rate
  • AI runs in text-only mode (no tool/command execution)

📄 File Upload Security

  • File type validation ensures only legitimate documents are accepted
  • Filename sanitisation removes dangerous characters and path manipulation
  • Content scanning detects embedded scripts and malicious payloads
  • Path traversal protection prevents unauthorised file access

🛡 Data Integrity

  • Atomic write operations prevent data corruption
  • Continuous monitoring detects unauthorised modifications
  • Automatic restoration from backup if corruption is detected
  • Protection against common injection and pollution attacks
  • Restrictive file permissions on sensitive data

Adversarial Test Results

Prompt injection and jailbreak testing outcomes

Full Pass
7 of 11 tests
Partial Fail
2 of 11 tests
Full Fail
2 of 11 tests

Test types included: multi-turn probes, social engineering attempts, encoded instructions, jailbreak techniques, architecture probes, and data extraction attempts. Testing is ongoing with continuous improvement to defences.

Security Q&A

Common questions from security and technology teams

"Where is our data stored?"
Your data stays under your firm's control. There are no third-party cloud databases or shared infrastructure.
"Does data leave the network?"
Only anonymised legal queries are sent to our AI provider for processing. All personally identifiable information is removed before any external communication. Our AI provider's commercial terms explicitly prohibit training on customer content.
"What happens to uploaded documents?"
Documents are stored securely. Text is extracted and PII is redacted before any AI processing. Original files are never exposed to external services.
"How are passwords stored?"
Industry-standard hashing with protection against timing attacks and credential enumeration. Passwords are never stored in plaintext.
"Is there an audit trail?"
Yes. All authentication events, suspicious activity, blocked connections, and intrusion attempts are logged with full timestamps and attribution.
"What about OWASP Top 10?"
Legal Brain is built with defences against all OWASP Top 10 vulnerabilities including XSS, injection, CSRF, path traversal, and broken authentication.
"Can the AI be tricked?"
Multiple layers of defence protect against prompt injection, jailbreak attempts, and social engineering. The AI cannot execute system commands. Regular adversarial testing ensures defences remain effective.
"SOC 2 / ISO 27001?"
Legal Brain's architecture inherently provides strong data sovereignty. Formal compliance documentation can be prepared to meet your firm's specific requirements.

Advanced Security Questions

Deeper technical questions and prepared responses

⚡ "What AI model is this running? Where do the queries go?"

Legal Brain uses a commercial large language model via API. Our AI provider's commercial terms explicitly prohibit training on customer content. Queries are processed and discarded. All PII is removed before any query is sent.

⚡ "Can we run this fully on-premise?"

Legal Brain can be deployed within your firm's infrastructure. On-premise deployment options are available - contact us to discuss your requirements.

⚡ "What about data retention? Can we enforce deletion policies?"

Users can delete documents and conversations at any time. Configurable retention policies are available to automatically purge records according to your firm's requirements.

⚡ "Do you have penetration testing results?"

Regular adversarial testing is conducted. A formal external penetration test can be commissioned if required as a condition of engagement.

⚡ "What's your incident response plan?"

Automated threat detection and blocking with real-time alerting. Comprehensive security logs support forensic investigation. A formal incident response plan can be provided.

⚡ "Can one user see another user's documents?"

No. Strict data isolation ensures each user can only access their own documents, search results, and conversation history.

⚡ "GDPR / Australian Privacy Act compliance?"

PII anonymisation is automatic and proactive. The architecture strongly supports compliance with Australian privacy requirements. Formal Data Processing Agreements and Privacy Impact Assessments can be prepared on request.

Enterprise Readiness

What we can provide to meet your firm's security requirements

Security Commitments

  • Data sovereignty: your firm's data stays under your control
  • PII protection is automatic: no configuration needed - client data is always anonymised before AI processing
  • Defence in depth: multiple layers of security from network to application to AI
  • Regular testing: adversarial and security testing conducted on an ongoing basis
  • Compliance support: architecture designed to support Australian Privacy Act requirements

Available on Request

  • Software Bill of Materials in standard formats
  • Third-party penetration testing can be commissioned
  • Compliance documentation: Privacy Impact Assessment, APP compliance mapping, NDB response plan
  • On-premise deployment: run Legal Brain entirely within your secure environment
  • Custom security requirements: we'll work with your IT team to meet your specific needs