Skip to content

Security

Control the boundary around sensitive legal work

Sanctum Lex lets firms govern deployment, data handling, model access, identity and egress around the sensitivity of the matter. For matters that cannot leave the firm's environment, private-perimeter deployment can operate without external model egress.

Architecture whitepaper

The operating principle

Security claims should match the deployed control.

Sanctum Lex distinguishes what the software supports, what the client has configured and what has been verified in that environment. That gives legal, IT and security teams a common description of the system they are actually approving.

Explicit deployment boundary

The signed deployment record identifies where Sanctum Lex runs, which model route is active, what may leave the environment and which controls were actually tested for the firm.

Private-perimeter option

For matters that cannot leave the firm's environment, Sanctum Lex supports local inference with outbound paths denied. In that configuration, there is no external model egress.

Governed external routes

If a firm approves an external model endpoint, Sanctum Lex treats it as governed egress and controls identity, matter scope, retention, routing and the data sent for inference.

Reviewable evidence

Security teams can review the data path, identity model, audit behaviour and control mapping rather than relying on an undifferentiated privacy claim.

Terms

What each term means here.

The client-specific deployment record remains the source of truth for which conditions are active, tested and contractually committed.

  • Private perimeter

    A client-approved environment in which matter data and inference remain within the defined boundary.

  • Zero egress

    Outbound paths are denied and inference is local. We use this term only when those conditions are actually active.

  • Governed egress

    An approved external model or integration route exists, but the route, permissions and data movement are explicit and controlled.

  • Zero data retention

    A model-provider retention control where contractually available. It is useful, but it is not the same as preventing inference data from leaving the client environment.

Controls

Security your committee can sign off

Sanctum Lex is designed to support GDPR, HIPAA and SOC 2-aligned controls. SAML SSO, scoped audit logs, IP allow lists and configurable retention policies are available as standard enterprise controls.

More about security
Aligned
GDPR
EU and UK data handling
Aligned
HIPAA
Protected health information
Aligned
SOC 2
Trust services criteria

For technical review

Put the architecture in front of the people who have to approve it.

Deployment topology, key handling, isolation boundaries, model routing and control mapping are available for technical review, together with a data handling statement that describes the client deployment rather than a generic SaaS environment.

Request a security review alongside the legal workflow.

We can walk the data path, model route, access controls and private-perimeter option alongside the legal workflow your lawyers want to evaluate.