In 30 minutes we show you Legis on your real documents — your frameworks, your method.
The technical and organisational measures Legis adopts under Article 32 of Regulation (EU) 2016/679 (GDPR) to protect the data processed with the Legis platform and its artificial intelligence assistant Lio.
This page describes the security measures and guarantees Legis S.r.l. (“Legis”) offers its Customers for the data processed with the Legis platform, including the artificial intelligence assistant Lio (the “Service”). In case of discrepancy, the Italian version prevails.
These measures apply to all data the Customer uploads to or generates in the Service, and to the data Legis processes to provide it. They are defined with reference to:
Legis may update these measures over time, provided that the overall level of protection is not reduced. Each version is identified by number and date; previous versions are available on request.
Legis is a multi-tenant SaaS platform for compliance management (governance, risk, compliance and privacy), supporting the GDPR, NIS2, ISO/IEC 27001, the AI Act, Italian Legislative Decree 231/2001 and related regulations. It is available in Italian and English.
Customer data is stored in the European Economic Area (EEA): databases, files and application services in data centres in Frankfurt (Germany), and the document editor on servers in Italy. Artificial intelligence providers also process data in the European Union (section 08).
All communication between users' devices and the Service is encrypted with TLS 1.2 or higher. Certificates are managed and renewed automatically, and unencrypted (HTTP) connections to the platform are redirected to HTTPS.
Data at rest is encrypted with AES-256 at infrastructure level. Encryption covers:
Documents are kept in private storage, never publicly accessible: they can be downloaded only through signed, expiring links.
Encryption keys are managed by the infrastructure providers with industry-standard procedures and periodic rotation. Service credentials are kept in encrypted secret managers, never in source code. Production and development environments are separate, with distinct databases and credentials.
The Service applies role-based access control (RBAC) following the principle of least privilege: differentiated roles with granular permissions, assigned to each user by the Customer's administrators.
Separation of data between Customers is enforced at database level: Row Level Security (RLS) is enabled on every table. The Customer a user belongs to is determined on the server side only, and cannot be manipulated from the browser.
Legis staff access Customer workspaces only when needed for support or security, and these accesses are logged. Administrative access to servers is not exposed to the Internet: it goes through an encrypted, authenticated channel.
The platform records relevant actions in an audit log:
Legis maintains documented disaster recovery procedures, which include:
The Service includes Lio, an artificial intelligence assistant for compliance work. The following safeguards apply to data processed through artificial intelligence.
Documents uploaded by the Customer (PDF, DOCX, XLSX, HTML, TXT) are read and indexed by a dedicated pipeline. The results are stored in the Customer's database, with the same isolation as all other data. Artificial intelligence providers receive only what each request needs: the question and the relevant parts of the documents.
Lio relies on specialised providers for language models, document indexing and semantic search, image reading and speech transcription. All of them process data in the European Union and act as sub-processors (section 10): they process data only to return the result.
When Lio searches the web, the search service receives only the queries Lio writes and the addresses of the pages to read, never the Customer's documents.
Legis maintains a documented security incident management procedure, which provides for:
To provide the Service, Legis relies on sub-processors: providers of cloud infrastructure, email and error-monitoring services, artificial intelligence and web search. Legis has a data processing agreement with each of them imposing data protection obligations equivalent to those Legis undertakes towards its Customers.
The list of sub-processors is available on request at [email protected]. Legis notifies the Customer of any change to the list at least 30 days in advance, during which the Customer may object.
For any question on data security and the protection of information: