Trust & Security

Compliance Documents

Public documents are available for immediate download. Restricted documents are shared with enterprise clients and law firm IT teams on request — click any locked document to contact us.

Available documents

6 documents
SecurityUpdated June 2026

Security Controls Overview

Summary of our technical and organizational security measures: AES-256 encryption, TLS 1.3, MFA enforcement, RBAC, and incident response. A readable one-pager for law firm IT departments.

SecurityShared on requestUpdated June 2026

Information Security Policy

High-level policy governing how Likan LLC manages information security across people, processes, and technology. Required by law firm IT departments for vendor approval.

SecurityShared on requestUpdated June 2026

Data Classification Policy

Defines how TheLawGPT classifies data: public, internal, confidential, and restricted — including attorney-client privileged content. Law firms use this to understand how their client data is handled.

SecurityShared on requestUpdated June 2026

Access Control Policy

Documents who inside Likan LLC can access which data, under what conditions, and how access is reviewed and revoked. Required by most enterprise vendor security questionnaires (VSQs).

SecurityShared on requestUpdated June 2026

Incident Response & Breach Notification Plan

Formalizes our 72-hour breach notification commitment. Covers escalation steps, internal roles, notification procedures, and customer communication. Required for law firm malpractice insurance questionnaires.

SecurityShared on requestUpdated June 2026

Vulnerability Management Policy

Describes our process for identifying, prioritizing, and remediating security vulnerabilities, including automated scanning cadence, CVSS severity thresholds, and patch timelines.

Coming soon

Data PrivacyUpdated June 2026

AI Data Privacy & Security Statement

Confirms that customer prompts, uploaded documents, and outputs are never used to train or improve AI models. Includes our no-training commitment, confidentiality controls, and data handling practices.

Coming soon
ComplianceUpdated June 2026

ABA Model Rule 1.6 Compliance Statement

One-page statement explaining how TheLawGPT's architecture is consistent with attorney confidentiality obligations under ABA Model Rule 1.6. Directly addresses the most common professional responsibility concern for US lawyers.

Coming soon
LegalUpdated June 2026

Data Processing Agreement (DPA) Template

Standard DPA for Business and Enterprise customers. Covers GDPR Article 28 obligations, Standard Contractual Clauses (SCCs) for US transfers, and our subprocessor commitments.

Coming soon
LegalUpdated June 2026

Acceptable Use Policy (AUP)

Standalone AUP separate from the Terms of Use. Defines permitted and prohibited uses of TheLawGPT. Law firm IT departments often require a dedicated AUP for their software approval process.

Coming soon
ComplianceUpdated June 2026

Subprocessor List

Dated, versioned PDF of all third-party subprocessors used by TheLawGPT, including their purpose, data accessed, and location. Enterprise procurement requires a fileable document, not a webpage.

Coming soon
SecurityUpdated Coming 2026

Penetration Test Report

Independent third-party penetration test of TheLawGPT's web application and API endpoints, covering OWASP Top 10, authentication, and session security. Conducted by a certified OSCP tester.

Coming soon
AI GovernanceUpdated June 2026

AI Model Card

What model powers TheLawGPT (Claude by Anthropic), what it can and cannot do, known limitations, accuracy caveats, and training data scope. Addresses ABA Formal Opinion 512 on AI competence.

Coming soon

Need something else?

Signed DPA, custom security questionnaire, or any document not listed here — contact us directly.

[email protected]