Multi-tenancy
Firm-level data isolation is enforced at the data layer. No firm reads another firm's matter. The isolation is not a UI filter. It is a database-level constraint. A query from firm A cannot return a row from firm B.
The trust layers in detail. Each one is enforced at the data layer, with the sign-off built into the product.
Last updated: 28 August 2026
7 sectionsFirm-level data isolation is enforced at the data layer. No firm reads another firm's matter. The isolation is not a UI filter. It is a database-level constraint. A query from firm A cannot return a row from firm B.
Within a firm, a user only sees the matters they are assigned to. Access control is enforced at the data layer, not in the UI. A user who is not assigned to a matter cannot retrieve that matter's records, drafts, or audit entries, even if they know the matter exists.
The firm's managing partner or in-house lead assigns matters to users. The system enforces the assignment. The firm controls who sees what.
Data is encrypted at rest and in transit. Object storage for attachments is encrypted. Backups are encrypted. The encryption keys are managed separately from the data they protect.
Every change to a case record is recorded in an append-only audit log with actor and timestamp. The log records who acted, what they did, and when. The audit log cannot be edited or deleted by the firm or by Leaglety.
The firm can export the audit log to show a client, a court, or a regulator who did what and when. The log is the firm's record, not ours.
The sign-off is built into the product. No AI output becomes final without a lawyer's sign-off. The firm configures the tier (one-tier or two-tier). The system enforces it. This is not a feature the firm can disable.
A rejected draft routes back to whoever produced it, with the reason attached. Every sign-off action is recorded in the audit log. The firm can show who checked what and when.
Read about review for the full flow.
The firm configures its practice areas, its templates, its checklists, its limitation rules, and its sign-off tier. The vendor does not configure the firm's workflow. The firm does. The system enforces the firm's configuration at the data layer.
The trust layers are not bolted on. They are the foundation the AI works on. The firm can show a client, a court, or a regulator that its work is in a system built for trust: data isolated, access controlled, encryption on, audit logged, sign-off enforced.
Read the about page for the mission, or the solutions page for the full product.
Book a 30-minute call and we will walk through the security and sign-off workflow.