L
LEXURA
|
LEGAL · SECURITY

Security Information

How we protect information, described at a high level.

Our approach

We apply technical and organisational measures appropriate to the service, the systems involved and the sensitivity of the data. No method of transmission or storage is completely secure.

Controls we operate

Encryption of data in transit, and at rest where appropriate.
Role-based access and least-privilege principles.
Authentication controls, with multi-factor authentication where the risk assessment requires it.
Logging and monitoring of relevant security events.
Backup and recovery processes proportionate to the service.
Supplier and subprocessor due diligence and contractual controls.
Incident-response and escalation procedures.

Where we process

eu-central-1 · Frankfurt
Documents & analysis

Application hosting and object storage on Amazon Web Services in the EU.

eu-west-2 · London
Authentication

Cognito authentication data (account email, password hash).

We do not claim ISO 27001 certification of our own. We do not train models on customer contracts.

Subprocessors

Amazon Web Services EMEA (hosting, storage, email delivery) — eu-central-1; authentication (Cognito) in eu-west-2.
Stripe (payments).
The large-language-model provider configured for analysis.

Retention

Storage lifecycle
90 days

Uploaded contracts and generated outputs are deleted automatically after 90 calendar days by a storage lifecycle rule. This is a calendar-day object expiry, not deletion immediately after a review.

Earlier on request
Account deletion

Deletion happens earlier on request, including confirmed account deletion.

Processing agreement

The current Data Processing Agreement (DPA / AVV, version 1.0, 10 September 2026) is published in full on this site. It is agreed together with the Processing Specification; for execution or a countersigned copy, email info@lexura.solutions. Customer contracts are not used to train models.

© 2026 · Lexura · All rights reserved