Pre-launch draft — Lexboard is not yet operating as a legal entity. These documents are drafts under legal review and are not yet in effect or binding.
Legal
Last updated: July 26, 2026. If you have found a security flaw in Lexboard, this page tells you how to report it, what we will do about it, and why you will not get in trouble for telling us.
1
Lexboard holds personal-injury case files: medical records, settlement figures, client identities, privileged attorney work product. A flaw that exposes one firm's matter to another firm is the worst outcome this product has. We would rather hear about it from you than from a client.
This policy is our standing authorization for good-faith security research within the scope below, and our commitment on what happens after you send the report.
2
lexboard.net and its subdomains, including the marketing site and the signed-in application./api/*./portal/*) and client-facing share and e-sign links.The class we care about most is cross-tenant access: any path by which one firm can read, write, or infer the existence of another firm's cases, clients, documents, communications, or ledger. We treat that as critical on arrival, ahead of anything else in the queue. The same goes for anything that lets a client portal user reach a matter that is not theirs.
3
Please do not test, and we generally will not act on, the following:
4
Email security@lexboard.net. One report per issue. Include:
We do not currently publish a PGP key. If you need to send something sensitive encrypted, say so in a first email and we will arrange a channel before you send it.
5
Remediation targets. These are targets, not a contractual SLA, and we will tell you when we are going to miss one: cross-tenant exposure or authentication bypass, fix or mitigation within 7 days; other high-severity issues, 30 days; medium, 90 days; low, on the normal roadmap. Lexboard is founder-operated, and we would rather publish targets we hit than enterprise numbers we do not.
6
If you make a good-faith effort to follow this policy, we will treat your research as authorized. Specifically, Lexboard will not initiate or support legal action against you under the Computer Fraud and Abuse Act, any state computer-crime statute, the anti-circumvention provisions of the DMCA, or our Terms of Service and Acceptable Use Policy, and we will not report you to law enforcement, for activity conducted within the scope and rules above. If a third party brings a claim about conduct that complied with this policy, we will say publicly and in writing that it was authorized.
Two honest limits. First, this safe harbour is ours alone — we cannot grant authorization on behalf of our subprocessors, our customers, or their clients. Second, it does not cover accessing, retaining, or disclosing real client data beyond the minimum needed to demonstrate the issue.
If you stumble into real customer data, stop immediately, do not save, copy, screenshot beyond what proves the finding, or share it, tell us the same day, and delete your copies when we confirm. Doing that is not a violation of this policy — it is what we are asking for.
7
8
We ask for 90 days from your first report before public disclosure, and we will usually be finished long before that. If we ship a fix earlier, you are free to publish once it is deployed. If we need longer because a fix is genuinely hard, we will ask, explain why, and expect you to be able to say no. We will not use the disclosure window to bury the issue, and we will not ask you to sign an NDA as a condition of reporting.
Where a vulnerability affected customer data, our incident-response obligations run in parallel: we notify affected firms without undue delay and in any event within 72 hours of confirming a breach, per our Data Processing Addendum.
9
We do not run a paid bug bounty. There is no reward table, no payout tier, and no promise of money for a report — not for a critical, not for a chain. If a bounty would change whether you spend your evening on this, we would rather you know that now than find out after the work.
What we do offer is a fast reply from the person who will actually write the fix, credit by name in section 10 if you want it, and a small token of thanks entirely at our discretion. If we ever fund a real bounty program, it will be announced on this page with its own terms.
We have not commissioned a third-party penetration test. We know firms and cyber insurers ask for the summary letter alongside the SOC 2 question, and the honest answer today is that neither exists. A scoped external test is planned; when it has been performed we will say so here, with the date and the firm that did it, and we will share the summary with customers under NDA. We will not describe internal review as a penetration test in the meantime.
10
No external reports have been credited yet — this section is empty because the program is new, not because we are withholding names. Researchers who report a valid issue and want credit will be listed here with the month of the fix.
11
We may update this policy as the platform and the program change. The version that governs your research is the one published at the time you report. Material changes will be reflected in the “last updated” date above.
12
Security reports: security@lexboard.net. Everything else, including vendor-diligence questionnaires: legal@lexboard.net.
Related: our Security & Trust summary, the Acceptable Use Policy, and our Continuity & Exit commitment.