Identity and access
Authentication, role, tenant, branch, matter, record, and support-access boundaries should remain fail-closed.
- Server-side authorisation
- Least-privilege roles
- Controlled support access
Use the Lexuno Trust Centre to understand the control areas that matter to legal practices and the evidence a firm should request before relying on them.
The existence of a control in product code is not the same as production assurance; the relevant evidence must match the deployed system.
Authentication, role, tenant, branch, matter, record, and support-access boundaries should remain fail-closed.
Security safeguards, operator obligations, retention, deletion, and cross-border processing require documented ownership.
High-impact changes, provider events, failures, approvals, and administrative access should produce usable evidence.
Backups, recovery, subprocessors, provider gates, and monitoring need current operational proof.
Trust is strongest when claims can be tied to a deployed version, configured provider, owner, and review date.
Identify personal, special, privileged, financial, trust, document, and audit information in scope.
Identify users, roles, systems, operators, subprocessors, transfers, and retention paths.
Review policies, architecture, contracts, configuration, tests, audit records, and recovery evidence.
Document gaps, owners, compensating controls, review dates, and any go-live conditions.
Lexuno does not use a regulatory framework as automatic proof that the deployed service complies with it.
POPIA, FICA, and professional rules define responsibilities; they do not certify a software product.
Certifications, penetration tests, hosting regions, uptime, and recovery results require current documentary evidence.
Navigation visibility and a signed-in session do not grant access to a tenant, branch, matter, document, client, or transaction.
Unavailable or unconfigured external services should remain visibly unavailable rather than returning synthetic success.
Questions about evidence, security responsibilities, regulatory frameworks, providers, and due diligence.
No. POPIA defines responsibilities and safeguards. Compliance depends on the deployed service, firm use, contracts, processing, policies, and current evidence.
Not necessarily. A buyer should verify the exact production deployment, configured providers, data locations, policies, monitoring, and operational ownership.
No. Access must be enforced server-side against the relevant tenant, branch, matter, record, and capability authority.
Use the contact page to request the current evidence appropriate to the service, data, provider, and due-diligence scope under review.
No. Lexuno provides software and product information. Firms should obtain appropriate professional advice for their own obligations and risk decisions.
Review the security architecture and contact Lexuno with the exact control questions relevant to your firm.