Data & privacy
Security is the foundation of LegalMike
We know the legal profession from the inside out and understand the importance of protecting your files and professional secrecy. LegalMike has therefore been developed according to the highest standards for privacy and information security.
Data and privacy guaranteed
Unlike generally available AI assistants, your data is not used to train AI models. The language models we use do not store your questions or answers either. This is established in our agreements with OpenAI regarding zero data retention. What we do store for you is encrypted within your own environment. This includes your questions, your answers, and the files you upload yourself. Only you have access to them. LegalMike processes your data exclusively within Europe and does not share it with third parties. The sub-processors we engage are listed in our data processing agreement and process data solely on our instructions and within Europe. This way, you maintain full control over your data within a highly secure environment. You can delete your history and files yourself at any time, and your organization can completely disable file uploads. You do not need to anonymize your documents before using them safely in LegalMike. You decide which data you input.
Data processing within Europe
All customer data is processed and stored within the European Economic Area. This applies to the entire chain: from the customer database on servers in Amsterdam to processing by the language model, text extraction from uploaded documents, and backups. Data transfer to countries outside the EEA does not take place.
Secure language models hosted in the EU
LegalMike’s language models are hosted by OpenAI Europe and process your questions via OpenAI’s European endpoint. Based on our agreements with OpenAI Europe, your data is not stored or shared with third parties. Your data is not used for training AI models by OpenAI or LegalMike. This ensures you always maintain full control over your interactions with LegalMike.
Security standards
OpenAI employs advanced security techniques such as AES-256 encryption and TLS 1.2+ for data traffic. Furthermore, OpenAI is certified for ISO 27001, 27017, 27018, and 27701, SOC 2 Type II, and CSA STAR, among others. LegalMike is also currently undergoing the process for ISO 27001 certification and will have completed it by 2026.
Encryption
All sensitive information within LegalMike is stored encrypted using AES-256-GCM and transmitted encrypted with TLS 1.2 and 1.3. Additionally, files you upload are encrypted with a per-user key in an environment separated from public legal sources. This way, your data is protected against unauthorized access and confidentiality is always guaranteed.
Authentication
To ensure that only authorized persons have access, LegalMike uses two-factor authentication (2FA) for end users and administrators, along with role-based access control (RBAC).
Security testing
LegalMike’s security is tested annually by an independent party. The most recent penetration test resulted in no Critical or High findings. We also continuously monitor for new vulnerabilities and resolve critical vulnerabilities within 24 hours, ensuring you always work in a secure environment.
Recovery
Backups of the databases are made daily, with a rotation of seven daily, four weekly, and twenty-four monthly backups. The backups are encrypted in two layers and stored within Europe. In the event of a malfunction or calamity, your data can be restored quickly and safely so you can always continue working. Restoration is tested periodically.
Laws and regulations
LegalMike complies with the laws and regulations applicable to our service, including the GDPR and the AI Act. Under the AI Act, LegalMike has been classified as a limited-risk AI system based on an independent assessment. We comply with the associated obligations regarding AI literacy (Article 4) and transparency (Article 50). We closely follow legal and technological developments to ensure you always work in a safe, reliable, and future-proof environment.
Trusted partner
Researchable is our IT partner, ISO 27001 certified, and operates according to ISO/IEC 25010:2023 and NEN7510 standards. This ensures that our innovations follow a rigorous process of testing and quality considerations.