Skip to content
LexGeniGet Your Free Trial
Data privacy and security

Your legal data. Protected by design.

Data minimization, controlled access, secure processing, customer control.

LexGeni AI recognizes that legal documents may contain confidential, privileged, personally identifiable information (PII), and other sensitive information. LexGeni AI works with each legal firm during onboarding to establish appropriate data-handling procedures before documents are introduced into the LexGeni AI environment.

Last updated: August 2026

Please note. Draft for review. This text describes LexGeni AI’s general approach and is not a substitute for an executed customer agreement. It should be reviewed by qualified counsel and coordinated with the Terms of Service, Privacy Policy, MSA, DPA and security documentation before publication.

01

PII review and redaction

Before customer documents are made available for AI processing, LexGeni AI works with the customer to establish a process for identifying and, where appropriate, redacting or removing PII and other sensitive information that is not required for the intended AI use case.

Customers remain responsible for determining which information may legally and contractually be provided to LexGeni AI, and for identifying any applicable confidentiality, privilege, privacy, data-residency or regulatory requirements.

Only provide the data necessary for the approved AI use case.

02

Two secure data integration options

LexGeni AI provides customers with flexible options for making approved legal documents available to the platform.

Option 1 — Customer-controlled data source

Keep your documents within your organization’s approved repository. Where supported by the customer’s environment and agreed integration architecture, legal documents can remain within a customer-controlled repository such as Microsoft SharePoint.

LexGeni AI can establish an authorized integration with the approved data source so that the AI solution accesses only the information required for the approved use case. Access can be limited according to the agreed permissions, identities, repositories and security requirements.

Customer SharePointAuthorized integrationLexGeni AI

This approach can reduce unnecessary duplication of customer information and allows the customer to maintain greater control over its source documents.

Option 2 — Secure LexGeni AI cloud storage

Customers may alternatively provide approved documents for storage within a dedicated LexGeni AI cloud storage environment configured for the customer’s AI solution. Before upload, the customer and LexGeni AI establish the approved data scope and applicable PII-redaction requirements.

Customer documentsPII review and redactionSecure transferLexGeni AI storageLexGeni AI

Access to customer data is restricted to authorized identities and services based on the security architecture established for the engagement.

03

Security controls

LexGeni AI uses a security-by-design approach intended to protect customer information throughout ingestion, storage, processing and access. Depending on the customer’s selected solution and agreed architecture, controls may include:

  • Encryption in transit and at rest
  • Identity and access management
  • Role-based and least-privilege access
  • Customer-specific data separation
  • Secure cloud storage
  • Restricted service-account permissions
  • Authentication and authorization controls
  • Logging and monitoring
  • Controlled document ingestion
  • Data-retention and deletion procedures
  • Security configuration reviews
  • PII minimization and redaction procedures

Specific controls and configurations are established based on the customer’s requirements, selected services, data classification and contractual obligations.

04

Customer data is used for the customer’s solution

Customer-provided information is processed for the purposes defined in the applicable customer agreement and approved LexGeni AI use case. The goal is to provide grounded legal AI capabilities while minimizing unnecessary exposure of customer information.

05

Shared responsibility

Protecting legal information is a shared responsibility.

LexGeni AI is responsible for
  • Implementing the security measures and data-handling practices applicable to the LexGeni AI environment, as defined in the customer agreement
The customer is responsible for
  • Determining whether information may be provided to LexGeni AI
  • Identifying applicable confidentiality, privilege, privacy, regulatory and data-residency requirements
  • Managing its own source systems and user permissions
  • Complying with applicable laws and professional obligations
06

Built for responsible legal AI

LexGeni AI combines customer-controlled data access, data minimization, PII-redaction practices, secure cloud infrastructure and controlled AI processing to help legal organizations adopt AI responsibly.

Your documents remain your data. Your access is controlled. Your AI solution is built around your requirements.

Security features and data-handling arrangements may vary by customer configuration and engagement. This page provides a general description of LexGeni AI’s approach and does not replace the terms of an applicable customer agreement, Data Processing Agreement or other contractual commitments.

Questions about data handling?

Security reviews, DPAs and data-residency requirements are handled during onboarding. Talk to us before any documents are provided.