Security & Trust
Security & Trust FAQ
Straight answers on sign-in, isolation, AI, HIPAA, and incidents. No certifications we don't have.
How do people sign in to LexMotus?
- Every firm login that uses a password also requires a FIDO2 security key or a passkey on your device. If you don't have one yet, LexMotus walks you through enrolling the first time you sign in. Authenticator-app codes (TOTP) are available only as a backup once a key is enrolled. Firms can also sign in through Microsoft 365 or Google Workspace single sign-on, which honors your identity provider's multi-factor settings.
What is FIDO2, and why does it matter?
- FIDO2 is a standard for hardware security keys and passkeys. The key only signs in on the real LexMotus site, so a fake login page can't capture anything usable. Passwords and six-digit codes can both be tricked out of people by convincing phishing pages. A FIDO2 key can't be.
What about my clients?
- Clients use a secure portal with a magic link sent by email or text, with no password to remember. Clients can also add a passkey. Firms can turn on per-matter email-only links and a second verification step for added protection. Sessions can be revoked, and new-device sign-ins alert the firm's staff.
How is one firm's data kept separate from another's?
- LexMotus uses row-level security in the database. Each firm's records are locked to that firm at the database itself, not just hidden by the screens in the app. Even if an application bug occurred, the database is designed to refuse to return another firm's rows.
Who at my firm can see what?
- Access is role-based: 60 permissions across five roles (Partner, Attorney, Paralegal, Intake, and System Administrator). You decide who can see which matters and documents. Clients only see the documents you choose to share with them.
Can I see who accessed a file?
- Yes. LexMotus keeps an audit log with more than 80 types of recorded actions, viewable by administrators. For HIPAA purposes, document views, downloads, and matter access are recorded in an immutable PHI access log.
Is LexMotus HIPAA-ready?
- LexMotus is ready to serve as a Business Associate under HIPAA, and a BAA template is available for signing. It includes PHI access logging, document-level PHI tagging, automatic idle session timeouts that firms can configure, HIPAA training acknowledgment tracking, and a breach notification timeline tracker. It does not claim a HIPAA "certification", since none exists.
Do you have SOC 2?
- Not yet. LexMotus plans to begin a SOC 2 observation period once the company is operating. Until then we don't claim any certification, and we're glad to answer your security questionnaire.
How does AI use my client files?
- LexMotus is decision support: it watches, warns, and drafts. It never files, serves, settles, signs, or sends anything on an attorney's behalf. Email is created as a draft in your Outlook Drafts folder by default. AI answers and drafts cite the source passages they used, so an attorney can check each one. Firms can set spending caps on AI use. Client data is never used to train AI models.
Where is my data stored?
- On Amazon Web Services in the US West (Oregon) region. Data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest in the database and in file storage.
Is LexMotus security-tested?
- LexMotus has been assessed internally against the OWASP Top 10 and API Top 10, with a composite Grade B, and is actively improving. We don't claim an independent third-party assessment.
What do I do if there's an incident?
- LexMotus includes a breach notification tracker with a 60-day deadline computation and HHS notification thresholds, and policies for HIPAA security and privacy. If we confirm an incident affecting your data, we will notify affected firms within 72 hours at the contact on file. Report a concern any time at incidents@lexmotus.com or support@lexmotus.com.
Who built LexMotus?
- LexMotus was built by Sean Jackson, who has 15 years in information security, from entry-level engineer to CISO, with earlier experience as a web developer, QA engineer, and penetration tester. He has led security programs at DigiCert and Podium, including a team that caught and contained an advanced persistent threat.
How do I ask more?
- Email sales@lexmotus.com or book a 15-minute demo.
For a longer technical write-up, see the Security & Trust details page.