Security
How Lextree secures your compliance records: encryption, tenant isolation, an automatic audit trail, and OWASP Top 10 practices on audited infrastructure.
Security isn't a feature we sell you. It's the condition for trusting the record at all.
Six commitments behind every record
Lextree is built for the people who lose sleep over compliance, so security isn’t a setting you switch on. These protections hold for every record, on every plan.
Encrypted in transit and at rest
Every byte that moves through Lextree travels over TLS 1.2 or higher, and the managed infrastructure it runs on encrypts stored data with AES-256.
Backups inherit the same encryption — there's nowhere your records sit in the clear.
Hosted in audited, SOC 2 facilities
Lextree runs on infrastructure certified to SOC 2 Type II, hosted in ISO 27001 data centers.
We inherit physical and environmental controls from an audited cloud provider and build our application security on top.
Role-based access, scoped to your data
Users see only what their role allows, and Lextree subscribers never see each other's data.
Permissions can be scoped by module and by record, so sensitive ownership, trust, or employment data stays separate from broader access.
An automatic trail of every change
Every create, update, and delete is logged automatically — in the same database transaction — with the user who made it, a timestamp, and the fields that changed.
Full audit-history access and extended retention come with Enterprise; sign-ins are logged separately, with device and IP.
Daily backups, point-in-time recovery
Your data is backed up on managed infrastructure, with point-in-time recovery to roll back to a moment before a mistake.
Backups are encrypted and kept apart from the live database.
Passwordless sign-in, SSO, and MFA
Sign in without passwords — Lextree never stores one to be stolen — with multi-factor authentication available and SAML or OIDC single sign-on on Enterprise plans.
Sessions run on encrypted, HttpOnly cookies, and access provisioning flows through your IdP.
Security is designed in, not added on
Lextree is compliance software built to hold the record that proves an organization met its obligations — the filing that went out, the resolution the board passed, the license that stayed current. A record like that is only worth keeping if it can be trusted, so security was never a later phase or a premium tier. It is the condition for the product working at all.
That shapes how the platform is built. Access controls enforce tenant boundaries, and database audit triggers record business-record changes in their history. These controls support a record of who changed information and when.
Infrastructure assurance
We’ll tell you plainly what we have and what we don’t. Lextree does not hold a SOC 2 report or an ISO certification of its own, and we won’t imply that it does. What we can show you is concrete and verifiable: the infrastructure we run on, the measures written into our Data Processing Agreement, and the controls described on this page.
Lextree runs on DigitalOcean, which publishes information about its SOC 2 Type II reports and infrastructure controls on its security page. Those reports concern DigitalOcean’s covered services and controls. Berkman remains responsible for Lextree’s application security and configuration.
Fewer places to fail
Lextree is one focused platform, not a general-purpose toolkit you assemble yourself. The data model, the permissions, and the audit trail are built together, not bolted on separately — so there are fewer seams for a mistake to slip through, and fewer settings you have to get exactly right to stay secure.
How your data stays protected
Encrypted at every step
Connections to Lextree and between the application and its managed database use TLS 1.2 or higher. Customer Data and retained backups are encrypted at rest using AES-256 or equivalent protection. Access controls protect data when it is processed by the application and supporting services; encryption does not prevent the authorized processing needed to provide the service.
Isolated by a tenant boundary
Lextree associates business records with a Subscription and scopes application data access to that Subscription. Tenant controls are designed to prevent one customer from accessing another customer’s records.
Customers can select US or EU hosting for the primary database, file storage, and retained backups. Operations and support are provided from the United States, and authentication, communications, monitoring, and temporary backup processing may occur outside the selected region. The DPA and Sub-Processor list describe those activities and applicable transfer safeguards.
Backed up and recoverable
Managed database backups support point-in-time recovery for service restoration. Backups are encrypted and held apart from the live database. Restoration is subject to the available recovery window and deletion safeguards; it does not guarantee recovery of a particular record or reverse a completed privacy deletion.
Access, permissions, and audit
Role-based, down to the record
Access in Lextree is layered. Users hold roles at the organization level, editor or viewer rights at the module level, and — on plans that include it — record-level access groups. Application queries enforce those permissions. API keys have a broader, Subscription-wide scope and are not limited by an individual user’s record permissions; administrators should share them only with trusted users and integrations. See the API Terms for the scope and safeguards.
An automatic change trail
Database audit triggers record business-record changes, including the acting user where available, time, and changed fields. Full audit-history access and extended retention are part of the Enterprise plan. Sign-in and security events are recorded separately, including user-agent and IP information. Retention periods are described in the DPA.
Practices informed by the OWASP Top 10
The OWASP Top 10 identifies common web application risks. The table below summarizes controls intended to address those risks; it is not an independent assessment or certification of Lextree.
| OWASP 2025 category | How Lextree addresses it |
|---|---|
| A01 Broken Access Control | Tenant scoping and application permissions, with separately documented Subscription-wide API-key access |
| A02 Security Misconfiguration | Hardened response headers (HSTS, frame-deny, nosniff, CSP), a strict host allowlist, and no debug surface in production |
| A03 Software Supply Chain Failures | Fully version-locked, hash-checked dependencies with automated update monitoring |
| A04 Cryptographic Failures | TLS in transit, platform AES-256 at rest, and API keys stored only as keyed HMAC hashes |
| A05 Injection | Parameterized database access and an ORM to reduce injection risk |
| A06 Insecure Design | Least-privilege roles and tenant scoping applied by default, not opt-in |
| A07 Authentication Failures | Passwordless sign-in with optional multi-factor authentication, plus SSO through a dedicated identity provider; encrypted, HttpOnly sessions |
| A08 Software or Data Integrity Failures | Cryptographically verified webhooks and sign-in flows; locked, hash-checked dependencies |
| A09 Security Logging & Alerting Failures | Automatic change logging plus centralized application, access, and error logs |
| A10 Mishandling of Exceptional Conditions | Configuration checks for required secrets and controlled production error responses |
Secure by default
The safe path is the default path. Sign-in is passwordless — Lextree never stores a password that could be stolen — and multi-factor authentication is available on top. API keys are high-entropy, hashed, and revocable at any time. The application ships with security headers on, a strict host allowlist, and secrets supplied only through the environment, never checked into code.
Watched and kept current
Dependencies are pinned to exact, hash-verified versions and monitored for new advisories automatically, so a vulnerable library surfaces as a pull request rather than a surprise. The public API is rate-limited per account to blunt abuse, and production activity is written to dedicated application, access, and error logs.
Your data remains yours
Export and deletion
Your records are yours to take. Lextree provides export tools during the Subscription and a support route for exports when access is inactive. Return and deletion follow the Terms of Service and DPA, including valid deletion instructions and mandatory deadlines. Subject to those requirements, operational backup copies expire within ninety days and archival copies within twelve months. Retained copies remain protected and beyond ordinary use; deletions are re-applied before restored data is used.
Lextree does not train or fine-tune models on Customer Data. Where semantic search is enabled, an open-source model on DigitalOcean infrastructure generates vector embeddings from record and document text and search queries. Model processing and the semantic-search index are in the Subscription’s hosting region: the United States for US-hosted Subscriptions and the European Union for EU-hosted Subscriptions. Customers remain in control of their own exports and independently selected external AI clients.
Breach notification in writing
Our Terms of Service and Data Processing Agreement require us to notify affected customers without undue delay after we become aware of a data breach. The notice includes available information, with further details provided as the investigation progresses, without undue further delay. The DPA also describes our security measures and international-transfer provisions; our sub-processor list identifies providers that process personal data on customers’ behalf.
The commitments, in the contract
Everything on this page is backed by documents you can read before you sign. Our Data Processing Agreement lists the technical and organizational measures we maintain; our sub-processor list names every third party that touches your data.
Data Processing Agreement
Our GDPR/UK/Swiss processing terms, with a full schedule of security measures (Annex 2) and the Standard Contractual Clauses.
Sub-processors
The current list of third parties we engage, what each processes, and where — with 30 days’ notice before any change.
Privacy Policy
What we collect, why, how long we keep it, and the rights you and your data subjects can exercise.
Terms of Service
The master agreement, including data ownership, export and deletion, and breach-notification commitments.
Have a security questionnaire, or want a copy of our DPA before you buy? Talk to our team →