Skip to content
Trust Centre

Security and Governance Claims Should Be Evidence, Not Decoration

Use the Lexuno Trust Centre to understand the control areas that matter to legal practices and the evidence a firm should request before relying on them.

Access authority Audit evidence Provider governance Data protection
Trust Domains

The control areas behind a legal-practice platform.

The existence of a control in product code is not the same as production assurance; the relevant evidence must match the deployed system.

Identity and access

Authentication, role, tenant, branch, matter, record, and support-access boundaries should remain fail-closed.

  • Server-side authorisation
  • Least-privilege roles
  • Controlled support access

Data protection

Security safeguards, operator obligations, retention, deletion, and cross-border processing require documented ownership.

  • Technical safeguards
  • Organisational measures
  • Processing records

Audit and operations

High-impact changes, provider events, failures, approvals, and administrative access should produce usable evidence.

  • Audit records
  • Incident handling
  • Reconciliation

Continuity and providers

Backups, recovery, subprocessors, provider gates, and monitoring need current operational proof.

  • Recovery exercises
  • Provider inventory
  • Readiness states
Due Diligence

Evaluate current evidence against the exact service you will use.

Trust is strongest when claims can be tied to a deployed version, configured provider, owner, and review date.

01

Define the data

Identify personal, special, privileged, financial, trust, document, and audit information in scope.

02

Map access and processing

Identify users, roles, systems, operators, subprocessors, transfers, and retention paths.

03

Inspect evidence

Review policies, architecture, contracts, configuration, tests, audit records, and recovery evidence.

04

Record residual risk

Document gaps, owners, compensating controls, review dates, and any go-live conditions.

Claim Discipline

What the Trust Centre does not claim without proof.

Lexuno does not use a regulatory framework as automatic proof that the deployed service complies with it.

No blanket compliance label

POPIA, FICA, and professional rules define responsibilities; they do not certify a software product.

No unverified certification

Certifications, penetration tests, hosting regions, uptime, and recovery results require current documentary evidence.

No permission assumption

Navigation visibility and a signed-in session do not grant access to a tenant, branch, matter, document, client, or transaction.

No hidden provider success

Unavailable or unconfigured external services should remain visibly unavailable rather than returning synthetic success.

Connected Guidance

Continue through the Lexuno platform.

Explore the product, operational controls, and connected workspaces related to this decision.

Primary Sources

Regulatory material behind this guidance.

These links support the regulatory context. They do not amount to legal advice or certify any software as compliant.

Trust Centre FAQ

Frequently Asked Questions

Questions about evidence, security responsibilities, regulatory frameworks, providers, and due diligence.

Does the Trust Centre certify Lexuno as POPIA compliant?

No. POPIA defines responsibilities and safeguards. Compliance depends on the deployed service, firm use, contracts, processing, policies, and current evidence.

Are security controls the same in every environment?

Not necessarily. A buyer should verify the exact production deployment, configured providers, data locations, policies, monitoring, and operational ownership.

Does role-based navigation prove authorisation?

No. Access must be enforced server-side against the relevant tenant, branch, matter, record, and capability authority.

Where can a firm request detailed evidence?

Use the contact page to request the current evidence appropriate to the service, data, provider, and due-diligence scope under review.

Does Lexuno provide legal or compliance advice?

No. Lexuno provides software and product information. Firms should obtain appropriate professional advice for their own obligations and risk decisions.

Ask for the evidence that matches your risk.

Review the security architecture and contact Lexuno with the exact control questions relevant to your firm.