Public Documentation

Lawie Docs

Security Overview

How Lawie approaches access control, data protection, auditability, secure delivery, resilience, and vulnerability handling.

This is a control overview, not a certification statement. Deployment evidence, executed agreements, and the customer’s enabled configuration are authoritative.

Identity and access

Tenant-scoped roles, least-privilege access, MFA/SSO where enabled, and controlled administrative access. Exact capabilities depend on the contracted deployment.

Data protection

Encryption in transit, protected storage, tenant isolation, scoped exports, and documented retention and deletion workflows.

Auditability

Security-relevant actions, workflow decisions, source provenance, and administrative changes are designed to produce reviewable records. Retention depends on tenant policy.

Secure delivery

Code review, automated checks, dependency and secret scanning, vulnerability handling, controlled deployment, rollback, and incident response are part of the engineering control model.

Resilience

Backups, restore procedures, monitoring, capacity controls, and incident playbooks are deployment controls; customer-specific RTO/RPO and SLA values require a contract.

AI safety

Source visibility, evidence-aware output, human approval for privileged actions, and feedback are safeguards, not guarantees of correctness.

Report a vulnerability

  1. Email security@lawielabs.com with a concise description, affected surface, and safe reproduction steps.
  2. Do not access other users’ data, disrupt service, use social engineering, or include customer data, credentials, or privileged legal content in the first message.
  3. Allow reasonable time to investigate and remediate before public disclosure. Lawie will acknowledge receipt and coordinate a disclosure timeline based on severity and verified impact.

Good-faith research within these boundaries should be reported through this channel. No reward or safe-harbor commitment is implied unless confirmed in writing.