Legistoby Hohmann
Trust and compliance

A cloud built for law firms, not a DIY server

Bar bodies allow cloud for law firms, provided the firm keeps control of its data and the provider is excluded from access to privileged information. That is exactly how we design the platform.

We don't train AI on your data

Firm files are never used to train models. A contractual guarantee, per-firm data isolation, and AI features that keep a human in the decision.

Data in the EU

Hosting and backups solely within the European Union.

Data isolation

Each firm's data is separated at the database level.

No training on your data

Firm files are never used to train AI models — a contractual guarantee.

Full auditability

A processing activity register and access log available as standard.

How we meet bar and GDPR requirements

RequirementHow we meet it
NRA resolution 86/2022 (cybersecurity)Encryption in transit and at rest, role-based access control, audit log.
OIRP Warsaw cloud standard (2020)Data processing agreement, EU data, no unrestricted provider access to content.
Professional secrecyDatabase-level isolation (RLS), firm-controlled key option for the most sensitive data.
GDPR Art. 28 (processing)A ready DPA template to sign, sub-processor list with locations.
AI Act (human in the decision)AI features as recommendations approved by a human, fully auditable.

Audit-ready posture

Data in the EU

Hosting and backups in the European Union. For sovereignty needs, an EU-jurisdiction instance.

Audit log

An access and change log available by default, on the firm's side.

Data Processing Agreement

A ready Art. 28 GDPR template for your lawyer to review and sign.

ISO 27001 planned

Certification is on the roadmap. Until then, we share security documentation and the DPA.

Defuse the data concern before it's raised

We'll walk through the security model and hand over the DPA template for your lawyer to review.