Pre-launch draft — Lexboard is not yet operating as a legal entity. These documents are drafts under legal review and are not yet in effect or binding.
Legal
Effective Date: May 11, 2026. Summary of Lexboard's security controls for customer vendor reviews. For technical questions, contact security@lexboard.net.
1
The full list of subprocessors is at /legal/subprocessors.
2
3
public.audit_log; available to firm admins for review.4
5
INSERT, UPDATE, DELETE and TRUNCATE are revoked from every signed-in role, so the people a row records cannot rewrite it; writes come only from server-side code and database triggers. Rows cover 100+ business-event types across case, client, document, financial, communication and permission data. Coverage is broad rather than total: caches, delivery queues, retry bookkeeping and per-user preferences are excluded on purpose. Money movements and external disclosures get richer overlay records per ABA Rules 1.15 and 1.6.6
7
We maintain a documented incident-response plan with severity tiers (SEV1: outage / data loss, SEV2: degraded service, SEV3: isolated bug). For SEV1:
8
9
We accept good-faith security research reports at security@lexboard.net. We commit to acknowledging within 2 business days and providing status updates every 5 business days until resolution. We won't pursue legal action against researchers who follow our coordinated-disclosure guidelines (see AUP § 9).
10
11
We commit to an independent third-party penetration test before general availability and at least annually thereafter, plus ad-hoc testing after major architectural changes. Results will be shareable under NDA on request to security@lexboard.net.
12
This page is reviewed quarterly and updated when material changes occur. Customers are notified by email to designated firm administrators for any change to encryption, hosting region, or sub-processor list.