Public Documentation
Lawie Docs
Security Overview
How Lawie approaches access control, data protection, auditability, secure delivery, resilience, and vulnerability handling.
This is a control overview, not a certification statement. Deployment evidence, executed agreements, and the customer’s enabled configuration are authoritative.
Identity and access
Tenant-scoped roles, least-privilege access, MFA/SSO where enabled, and controlled administrative access. Exact capabilities depend on the contracted deployment.
Data protection
Encryption in transit, protected storage, tenant isolation, scoped exports, and documented retention and deletion workflows.
Auditability
Security-relevant actions, workflow decisions, source provenance, and administrative changes are designed to produce reviewable records. Retention depends on tenant policy.
Secure delivery
Code review, automated checks, dependency and secret scanning, vulnerability handling, controlled deployment, rollback, and incident response are part of the engineering control model.
Resilience
Backups, restore procedures, monitoring, capacity controls, and incident playbooks are deployment controls; customer-specific RTO/RPO and SLA values require a contract.
AI safety
Source visibility, evidence-aware output, human approval for privileged actions, and feedback are safeguards, not guarantees of correctness.
Report a vulnerability
- Email security@lawielabs.com with a concise description, affected surface, and safe reproduction steps.
- Do not access other users’ data, disrupt service, use social engineering, or include customer data, credentials, or privileged legal content in the first message.
- Allow reasonable time to investigate and remediate before public disclosure. Lawie will acknowledge receipt and coordinate a disclosure timeline based on severity and verified impact.
Good-faith research within these boundaries should be reported through this channel. No reward or safe-harbor commitment is implied unless confirmed in writing.