Legis S.r.l.

Security measures

Version 1.2 · 25 September 2026

The technical and organisational measures Legis adopts under Article 32 of Regulation (EU) 2016/679 (GDPR) to protect the data processed with the Legis platform and its artificial intelligence assistant Lio.

This page describes the security measures and guarantees Legis S.r.l. (“Legis”) offers its Customers for the data processed with the Legis platform, including the artificial intelligence assistant Lio (the “Service”). In case of discrepancy, the Italian version prevails.

Section 01

Scope and references

These measures apply to all data the Customer uploads to or generates in the Service, and to the data Legis processes to provide it. They are defined with reference to:

  • Article 32 of Regulation (EU) 2016/679 (GDPR), security of processing;
  • Article 21 of Directive (EU) 2022/2555 (NIS2), transposed in Italy by Legislative Decree 138/2024, cybersecurity risk-management measures;
  • the Italian National Framework for Cybersecurity and Data Protection;
  • ISO/IEC 27001:2022, information security management systems.

Legis may update these measures over time, provided that the overall level of protection is not reduced. Each version is identified by number and date; previous versions are available on request.

Section 02

Architecture and infrastructure

2.1 Overview

Legis is a multi-tenant SaaS platform for compliance management (governance, risk, compliance and privacy), supporting the GDPR, NIS2, ISO/IEC 27001, the AI Act, Italian Legislative Decree 231/2001 and related regulations. It is available in Italian and English.

Feature
Details
Service model
Multi-tenant SaaS for companies, professional firms and compliance consultants.
Authentication
Email and password or a Google or Microsoft account, with multi-factor authentication (MFA).
Hosting
Data centres in the European Union: Frankfurt (Germany) and, for the document editor, Italy.
Cloud providers
Certified to ISO/IEC 27001.

2.2 Data location

Customer data is stored in the European Economic Area (EEA): databases, files and application services in data centres in Frankfurt (Germany), and the document editor on servers in Italy. Artificial intelligence providers also process data in the European Union (section 08).

Section 03

Encryption and data protection

3.1 Data in transit

All communication between users' devices and the Service is encrypted with TLS 1.2 or higher. Certificates are managed and renewed automatically, and unencrypted (HTTP) connections to the platform are redirected to HTTPS.

3.2 Data at rest

Data at rest is encrypted with AES-256 at infrastructure level. Encryption covers:

  • databases (structured data, metadata, configuration);
  • file storage (uploaded documents and attachments);
  • backups;
  • vector indexes (embeddings) and document excerpts used by artificial intelligence;
  • access tokens for the Google and Microsoft integrations, additionally encrypted at application level (AES-256-GCM).

Documents are kept in private storage, never publicly accessible: they can be downloaded only through signed, expiring links.

3.3 Key and credential management

Encryption keys are managed by the infrastructure providers with industry-standard procedures and periodic rotation. Service credentials are kept in encrypted secret managers, never in source code. Production and development environments are separate, with distinct databases and credentials.

Section 04

Access control

4.1 Authorisation model

The Service applies role-based access control (RBAC) following the principle of least privilege: differentiated roles with granular permissions, assigned to each user by the Customer's administrators.

4.2 Authentication

  • sign-in with email and password, or with a Google or Microsoft account;
  • multi-factor authentication (MFA) with an authenticator app, which the Customer can make mandatory for all its users;
  • sessions based on signed tokens (JWT) valid for one hour and renewed automatically with rotating refresh tokens; each session lasts at most 72 hours.

4.3 Isolation between Customers

Separation of data between Customers is enforced at database level: Row Level Security (RLS) is enabled on every table. The Customer a user belongs to is determined on the server side only, and cannot be manipulated from the browser.

4.4 Access by Legis staff

Legis staff access Customer workspaces only when needed for support or security, and these accesses are logged. Administrative access to servers is not exposed to the Internet: it goes through an encrypted, authenticated channel.

Section 05

Monitoring, logging and audit

5.1 Audit logs

The platform records relevant actions in an audit log:

  • for each action: who (user), what (action and object) and when (date and time);
  • audit logs are immutable: no user, including the Customer's administrators, can modify or delete them;
  • they are kept for the whole term of the contract;
  • sign-ins to the platform are recorded with IP address, device, date, time and outcome.

5.2 Infrastructure monitoring

  • continuous infrastructure monitoring, with automatic alerts on the status of services;
  • automatic collection and analysis of application errors.
Section 06

Backup, business continuity and disaster recovery

6.1 Backup

Parameter
Value
Frequency
Daily, automatic.
Retention
7 days.
Encryption
AES-256.
Location
European Union.

6.2 Business continuity and disaster recovery

Legis maintains documented disaster recovery procedures, which include:

  • recovery objectives (RTO and RPO) defined for critical services;
  • recovery procedures tested periodically;
  • a documented, up-to-date business continuity plan.
Section 07

Secure development and application security

  • development following secure coding practices (OWASP Top 10);
  • mandatory code review before every release to production;
  • automated tests and automated security analysis of changes;
  • server-side input validation;
  • automatic monitoring of vulnerabilities in software dependencies, with regular updates;
  • automated releases using short-lived credentials, with no permanent access keys;
  • separate development and production environments;
  • a web application firewall (WAF) in front of application services;
  • DDoS protection on every entry point to the Service;
  • the servers running the artificial intelligence services accept only traffic that comes through the web application firewall.
Section 08

Security of processing through artificial intelligence

The Service includes Lio, an artificial intelligence assistant for compliance work. The following safeguards apply to data processed through artificial intelligence.

8.1 Isolation and no sharing of data

  • Customer data is not used to train artificial intelligence models, either by Legis or by its providers;
  • Customer data is not shared with other Customers or used to improve the service offered to other Customers;
  • Lio accesses data with the permissions of the user working with it: the database applies the same isolation and permission rules, and changes go through the same checks;
  • Lio's answers are based only on the data of the workspace in which it is used, and contain no data of other Customers;
  • processing through artificial intelligence is subject to the same security measures described on this page.

8.2 Document processing

Documents uploaded by the Customer (PDF, DOCX, XLSX, HTML, TXT) are read and indexed by a dedicated pipeline. The results are stored in the Customer's database, with the same isolation as all other data. Artificial intelligence providers receive only what each request needs: the question and the relevant parts of the documents.

8.3 Artificial intelligence providers

Lio relies on specialised providers for language models, document indexing and semantic search, image reading and speech transcription. All of them process data in the European Union and act as sub-processors (section 10): they process data only to return the result.

When Lio searches the web, the search service receives only the queries Lio writes and the addresses of the pages to read, never the Customer's documents.

Section 09

Organisational measures

9.1 Personnel

  • all personnel authorised to process data are bound by confidentiality agreements;
  • periodic training on data protection and information security;
  • periodic review of access rights and privileges.

9.2 Incident management

Legis maintains a documented security incident management procedure, which provides for:

  • notifying the Customer of any personal data breach without undue delay and, where possible, within 72 hours of its discovery;
  • containment, investigation and remediation of the incident;
  • documentation of the incident: its nature, impact and corrective measures.
Section 10

Sub-processors

To provide the Service, Legis relies on sub-processors: providers of cloud infrastructure, email and error-monitoring services, artificial intelligence and web search. Legis has a data processing agreement with each of them imposing data protection obligations equivalent to those Legis undertakes towards its Customers.

The list of sub-processors is available on request at [email protected]. Legis notifies the Customer of any change to the list at least 30 days in advance, during which the Customer may object.

Section 11

Contacts

For any question on data security and the protection of information:

Security and privacy