Skip to main content

Trust.

Invoice data is sensitive. Contract data is sensitive. The findings we deliver are sensitive. This page documents how LEGERIS handles every category — encryption, retention, no-training disclosure, subprocessor model, compliance roadmap. Every claim here is the contract.

Updated 26 July 2026

How we handle your data.

A LEGERIS engagement begins when a client emails us their invoices. From that moment, the data is treated as restricted material — segregated by client organisation, encrypted at every transit boundary, and retained only as long as the engagement and any post-engagement audit-trail requirement demands. Access inside LEGERIS is limited to the engagement’s assigned forensic team. No part of the data is used to train AI models, sold to third parties, or shared with anyone outside the engagement without your explicit written authorisation.

Encryption posture.

In transit

All inbound submissions, outbound deliveries, and internal service-to-service traffic ride TLS 1.3 (or, where the client side cannot negotiate 1.3, TLS 1.2 minimum). No unencrypted HTTP fallback. The TLS certificate chain is managed by our hosting provider with industry-standard rotation cadence.

At rest

Invoice bytes, audit snapshots, knowledge-base documents, and PDF reports are persisted in a private object store with provider-managed encryption at rest. Database rows containing structured findings are similarly encrypted by the database provider’s default disk-encryption posture. Application-level encryption of the most sensitive payloads (customer-managed key model) is on the SOC 2 roadmap.

Retention.

Default retention for raw invoice bytes and the immutable audit snapshot: ninety days after engagement delivery. After that window, the raw bytes are permanently deleted from the object store; the structured audit snapshot is retained indefinitely as the legal record of the audit (without the underlying invoice bytes attached).

Engagement-specific retention exceptions are honored. If your contract, your regulator, or your legal team requires a different window — longer for litigation hold, shorter for immediate deletion after final report — that requirement is honored as part of the engagement scope.

Aggregated, anonymised finding data is retained for benchmarking purposes (see the subprocessor section below for the model). The anonymisation pipeline is documented and audited; no aggregate ever exposes per-client identifiers.

Deletion on request: any time, by emailing legal@legeris.ai.

Load-bearing

We do not train models on your data.

This is the single most important commitment on this page, so it is stated explicitly: client invoice data, contract data, and audit findings are never used to train, fine-tune, or otherwise improve any AI model operated by LEGERIS or any of our subprocessors. Our agreements with the language-model providers we use contractually prohibit them from training on data submitted through their API.

The deterministic engines that decide every LEGERIS finding do not involve a training step at all — they are rule-based code with versioned behaviour. The language-model surfaces (which propose candidate findings that deterministic engines then verify) are configured with provider-side opt-out from training where applicable, and contractually bound where the configuration option does not exist.

Subprocessor model.

LEGERIS uses the following categories of subprocessors to deliver our service: a leading enterprise document-OCR provider operating from Microsoft Azure data centers; a primary database-and-storage provider; and one or more frontier large-language-model providers operating under data-processing agreements that contractually prohibit training on submitted data.

The named list of specific subprocessors — vendor, function, data category, processing location — is available on request to qualified clients as part of a security review process. The named list is provided under NDA where the security review process warrants it, which it usually does.

Subprocessor changes (additions, replacements, processing-location changes) are notified to engaged clients via the security@legeris.ai mailing list with at least thirty days’ notice, except where the change is required for security reasons and a longer notice window would compromise the protection it provides. In such cases the notification is sent as soon as the security change has been deployed.

For the named subprocessor list, write to security@legeris.ai.

Compliance roadmap.

  • SOC 2 Type II

    Pre-audit

    Pre-audit. Formal kickoff scheduled to align with our first paying engagement. Pre-audit security controls follow SOC 2 trust principles.

  • GDPR

    Aligned

    GDPR-aligned data handling. Specific clauses (DPA, subprocessor notification, DSAR) available on engagement.

  • ISO 27001

    Not pursued

    Not currently pursued.

  • HIPAA

    Not in scope

    Not in scope. LEGERIS is not currently positioned to handle PHI.

  • PCI-DSS

    Not in scope

    Not in scope. LEGERIS does not process card data.

Status updates land here as they’re earned, never before.

Data subject rights.

If your organisation, or any individual whose data is included in material submitted to LEGERIS, requests access to, correction of, portability of, or deletion of that data, the request is honored.

Send the request to legal@legeris.ai. Expected response time: within five business days for an acknowledgment, with the substantive response delivered in line with the applicable jurisdiction’s statutory window (thirty calendar days under GDPR; varies under other regimes).

The deletion request is honored even when the contract retention window has not yet expired — we do not hold data hostage past a client’s explicit request to delete it. The only exception is data subject to litigation hold, which LEGERIS will not delete during the hold window.

Incident response.

In the event of a security incident materially affecting client data, LEGERIS will notify affected clients within seventy-two hours of the incident being confirmed, via the security@legeris.ai mailing list and direct email to the engagement’s primary contact. Notification will include the nature of the incident, the affected data categories, the remediation steps taken, and the recommended client-side response if any.

Responsible disclosure: if you have identified a security vulnerability in any LEGERIS surface, please report it to security@legeris.ai. We will acknowledge receipt within two business days.

Security contact.

Ready for a security review.

Send your security questionnaire, your DPA template, your subprocessor-list request — we will respond within two business days.

Email security@legeris.ai