Security & trust
Trust, built into every layer.
Your documents contain the terms your business runs on. Here's exactly how Lawlift protects them — where they're hosted, how they're encrypted, and what happens (and doesn't happen) when AI touches them.
Protected by default, not by request.
Case data for Document Automation is encrypted on your device before it ever reaches our servers. Every AI request runs on EU infrastructure, under contracts that forbid training on your data. And every certification on this page is independently audited — not self-declared.
How we protect your documents.
-
Hosting & infrastructure
The application runs on servers in Germany, administered by Lawlift. AI processing takes place on EU infrastructure. Your data does not leave the EU.
-
Encryption — and what changes when AI is involved
For Document Automation, your data is encrypted on your device before it's transmitted — a zero-knowledge design where the decryption key never reaches our servers. Lawlift Intelligence's AI features need to read your document to draft, edit, or review it, so that content does pass through our servers and our AI providers for processing — it is not persisted once the task completes. Every connection is secured with TLS/SSL.
-
AI processing
Lawlift Intelligence runs exclusively on Microsoft Azure OpenAI Service and AWS Bedrock — never OpenAI or Anthropic's own infrastructure directly — because that's how we can guarantee EU-only processing. Both are bound by data processing agreements, EU standard contractual clauses, and the additional safeguards required for legal professionals under German lawyers' professional confidentiality rules (BRAO). Your content passes through these services to be processed, but nothing is persisted once the task completes, and we never train any model on your data.
-
Access control
Sign in with SSO via Microsoft Entra ID or OpenID Connect/OAuth. Two-factor authentication protects unrecognized devices. Four predefined roles, or your own custom roles, control exactly who can see and do what.
-
Compliance & contracts
Lawlift is GDPR compliant by design and ISO/IEC 27001 certified for information security management. A Data Processing Agreement is available as part of every contract.
the EU
Common questions
- Where is my data stored?
- On servers in Germany. AI processing happens on EU infrastructure — your data never leaves the EU.
- Does Lawlift train AI models on my data?
- No. We never train on your data, it is not persisted beyond completing the task, and our AI providers (Microsoft Azure OpenAI Service, AWS Bedrock) are contractually bound not to train on it either.
- Is my data encrypted?
- For Document Automation, yes — your data is encrypted on your device before transmission, a zero-knowledge design where the decryption key never reaches our servers. For Lawlift Intelligence's AI features, your document content passes through our servers and AI providers to be processed (that's what makes AI-assisted drafting and review possible), though it isn't persisted afterward. Every connection is always secured with TLS/SSL.
- Can I get a Data Processing Agreement (DPA)?
- Yes. A DPA is available as part of every contract — just ask your point of contact or reach out below.
- Is Lawlift GDPR compliant?
- Yes. Lawlift is GDPR compliant by design and ISO/IEC 27001 certified for information security management.
Have a security question we didn't answer?
Request our full security documentation or talk to our team directly.
Let’s talk!
Schedule an expert callTalk to one of our automation experts. We’ll walk you through Lawlift, answer your questions, and explore how it fits your workflow — no strings attached.