Available documents
6 documentsSecurity Controls Overview
Summary of our technical and organizational security measures: AES-256 encryption, TLS 1.3, MFA enforcement, RBAC, and incident response. A readable one-pager for law firm IT departments.
Information Security Policy
High-level policy governing how Likan LLC manages information security across people, processes, and technology. Required by law firm IT departments for vendor approval.
Data Classification Policy
Defines how TheLawGPT classifies data: public, internal, confidential, and restricted — including attorney-client privileged content. Law firms use this to understand how their client data is handled.
Access Control Policy
Documents who inside Likan LLC can access which data, under what conditions, and how access is reviewed and revoked. Required by most enterprise vendor security questionnaires (VSQs).
Incident Response & Breach Notification Plan
Formalizes our 72-hour breach notification commitment. Covers escalation steps, internal roles, notification procedures, and customer communication. Required for law firm malpractice insurance questionnaires.
Vulnerability Management Policy
Describes our process for identifying, prioritizing, and remediating security vulnerabilities, including automated scanning cadence, CVSS severity thresholds, and patch timelines.
Coming soon
AI Data Privacy & Security Statement
Confirms that customer prompts, uploaded documents, and outputs are never used to train or improve AI models. Includes our no-training commitment, confidentiality controls, and data handling practices.
ABA Model Rule 1.6 Compliance Statement
One-page statement explaining how TheLawGPT's architecture is consistent with attorney confidentiality obligations under ABA Model Rule 1.6. Directly addresses the most common professional responsibility concern for US lawyers.
Data Processing Agreement (DPA) Template
Standard DPA for Business and Enterprise customers. Covers GDPR Article 28 obligations, Standard Contractual Clauses (SCCs) for US transfers, and our subprocessor commitments.
Acceptable Use Policy (AUP)
Standalone AUP separate from the Terms of Use. Defines permitted and prohibited uses of TheLawGPT. Law firm IT departments often require a dedicated AUP for their software approval process.
Subprocessor List
Dated, versioned PDF of all third-party subprocessors used by TheLawGPT, including their purpose, data accessed, and location. Enterprise procurement requires a fileable document, not a webpage.
Penetration Test Report
Independent third-party penetration test of TheLawGPT's web application and API endpoints, covering OWASP Top 10, authentication, and session security. Conducted by a certified OSCP tester.
AI Model Card
What model powers TheLawGPT (Claude by Anthropic), what it can and cannot do, known limitations, accuracy caveats, and training data scope. Addresses ABA Formal Opinion 512 on AI competence.
Need something else?
Signed DPA, custom security questionnaire, or any document not listed here — contact us directly.
[email protected]