Security & Trust

LegalFormsOS — Security & Trust

Last updated: 2026-07-14. Protecting your clients' most sensitive information is the core of LegalFormsOS. This page summarizes the security program in plain language. A detailed, re-runnable evidence report is available to customers and their security teams on request.

WHERE YOUR PRIVACY MEANS MOST. Family-law filings contain some of the most sensitive data a person has — Social Security numbers, financial accounts, information about children. We built LegalFormsOS around protecting it.

ENCRYPTION EVERYWHERE. All traffic is encrypted in transit with TLS (HTTPS is enforced with HSTS). Sensitive fields — Social Security numbers and financial account numbers — are encrypted at rest with AES-256-GCM, with a unique initialization vector per value. Passwords are never stored; they are hashed with the memory-hard scrypt algorithm. Sensitive identifiers are render-only: never written to logs, analytics, search, or exports.

STRICT ACCESS CONTROL. Every account (organization) is isolated — one customer can never see another's data. Access inside an account is role-based and least-privilege. Two-factor authentication protects sign-in. Sessions time out on inactivity and have a hard cap, and every state-changing request is protected against cross-site request forgery.

CONTINUOUS SECURITY TESTING. We run an automated 13-layer production security audit that checks transport security, headers, authentication, session management, tenant isolation, injection defenses, encryption at rest, secrets management, data deletion, rate limiting, dependency vulnerabilities, logging, and hardening — on demand and on every change. Dependencies are scanned for known vulnerabilities. We maintain a documented vulnerability-management and penetration-testing program and an incident-response plan.

YOU CONTROL YOUR DATA — AND ITS DELETION. You choose per-client data-retention modes. When you delete your account, it is recoverable for 30 days and then permanently and irreversibly purged: every record is scrubbed per a documented data-cascade map, files are securely erased, and user records are anonymized. We can tell you exactly what happens to every category of record.

DATA RESIDENCY. Your data is stored and processed in the United States (onshore). We do not store your matter data offshore. Our sub-processors are listed at /p/subprocessors.

FOR SECURITY TEAMS. We are happy to complete security questionnaires and to provide our current security audit report, data-processing agreement, deletion/data-cascade map, and incident-response summary. Email security@legalformsos.com.

HONEST NOTE. No system is "unhackable," and we don't claim to be. What we commit to is a rigorous, transparent, continuously-tested security program, honest disclosure if something goes wrong, and giving you the evidence to verify our claims. Independent third-party penetration testing and formal audits (e.g., SOC 2) are part of our roadmap and are performed by external assessors.

Contact: security@legalformsos.com.

Disclaimer

LegalFormsOS is document automation software only — not legal advice, not a law firm, not affiliated with any court or government agency.