Data security, by the book.
We have partnered with leading technology providers that operate under the same security regime the banking industry demands. Every document processed on LexRam TSR is stored under the most stringent security standards, so you get the relief of knowing your records are protected end to end.
The document you upload is never used to train any Artificial Intelligence, and always remains within the safety limits set for your organisation. LexRam TSR Data Storage is built on Supabase, a platform independently certified for SOC 2 Type 2 and ISO 27001.
Your documents stay yours
Each organisation’s documents live in its own isolated space, no cross-tenant reads, ever. Files are processed only to produce your report, and every finding cites the exact source page it came from.
Compliance
Certifications held by the infrastructure LexRam TSR Data Storage is built on.
SOC 2 Type 2 | LexRam TSR
LexRam TSR Data Storage is built on Supabase, whose infrastructure is SOC 2 Type 2 audited, an important standard when handling sensitive customer data. The report is available to customers on request.
ISO 27001 | LexRam TSR
LexRam TSR Data Storage runs on infrastructure certified against ISO 27001, the internationally recognised standard for information security management systems (ISMS), rigorous, independently audited controls that protect customer data. The certificate is available on request.
GDPR & European compliance | LexRam TSR
LexRam TSR Data Storage supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database in-region, and a Data Processing Agreement (DPA) is available on request for customers who need a formal contract under GDPR.
Data
Data encryption | LexRam TSR
All customer data is encrypted at rest with AES-256 and in transit via TLS. Sensitive information such as access tokens and credentials is encrypted at the application level before it is ever stored in the database.
Data residency | LexRam TSR
When your project is created, the database, authentication service, and document storage are hosted together in a single cloud region. Your data stays in-region. European in-region hosting is available on request.
Backups | LexRam TSR
Databases are backed up every day, with point-in-time recovery available so that data can be restored to any moment, not just to last night’s snapshot.
Data Processing Agreement | LexRam TSR
A Data Processing Agreement (DPA) is available on request for customers who need a formal data processing contract under GDPR.
Configuration
OTP-verified sign-in | LexRam TSR
Every account signs in through one-time password (OTP) verification, a second factor tied to your registered contact, not just a password.
Role-based access control | LexRam TSR
Within your organisation, members are granted scoped roles, owners, admins, and members see only the cases, documents, and billing functions their role permits. Access is enforced at the database level, not just in the interface.
Vulnerability management | LexRam TSR
The underlying platform works with industry experts to conduct regular penetration tests, and our own code is continuously scanned for vulnerabilities and reviewed internally.
DDoS protection & spend control | LexRam TSR
Traffic is protected at the edge against Distributed Denial of Service attacks, with rate limiting and brute-force prevention on authentication routes. And because billing is prepaid, your spend is capped by design, you can never spend more than you have recharged.
Questions about how your data is handled?
Compliance reports, our DPA, and residency options are available on request.