Security

Security built for law firms.

Protecting case information isn't a feature. It's the foundation.

Lextiff is designed with practical security principles to help plaintiff firms organize, manage, and protect their data. Every account, case, document, and workflow is built with security in mind.

๐Ÿ—„๏ธ
15 min
Backup frequency
โฑ๏ธ
PITR
Point-in-time recovery
๐Ÿ”’
TLS 1.2/1.3
Encrypted in transit
๐Ÿงพ
SHA-256
Backup integrity verified
๐Ÿข
Multi-tenant
Firm-level isolation
๐Ÿ‘ค
RBAC
Role-based access control
๐Ÿ“‹
Audit logs
Every action traceable
๐Ÿ›Ÿ
DR plan
Documented recovery process

Compliance

What's in place today โ€” and what's next.

We only list what we've actually implemented. No badges we don't own.

Current

โœ“ Role-Based Access Control (RBAC)
โœ“ Audit Logging
โœ“ Point-in-Time Recovery (PITR)
โœ“ Disaster Recovery Plan
โœ“ Backup Integrity Verification (SHA-256)
โœ“ Encryption in Transit (TLS 1.2/1.3)
โœ“ PHI Field-Level Encryption
โœ“ BAA Available on Request

Roadmap

โ—‹ ISO 27001
โ—‹ SOC 2 Type I
โ—‹ SOC 2 Type II
โ—‹ HIPAA Certification
โ—‹ WCAG Accessibility Conformance
โ—‹ ISO 27701 (Privacy)
โ—‹ Annual Third-Party Penetration Test

Lextiff is designed to support these standards โ€” this page describes our architecture and practices, and does not constitute a certification. Formal certifications, where pursued, will be announced separately.

Infrastructure

Where your data lives.

We know firms want to understand the infrastructure behind the platform, not just take security claims on faith.

๐Ÿ–ฅ๏ธ Application
โ†“
๐ŸŒ Nginx
โ†“
โš™๏ธ Laravel
โ†“
๐Ÿ—ƒ๏ธ MariaDB
โ†“
โ˜๏ธ Backblaze B2
โ†“
๐Ÿงฌ Versioned Backups
โ†“
โฑ๏ธ Point-in-Time Recovery
โ˜๏ธ

Secure cloud infrastructure

๐ŸŒ

Multi-region backups

๐Ÿ“ก

Continuous monitoring

๐Ÿ›Ÿ

Disaster recovery planning

๐Ÿ—„๏ธ

Secure object storage

๐Ÿ”’

TLS encryption

โš™๏ธ

High availability architecture

๐Ÿ”

Redundant systems

Our approach

Security by Design.

Lextiff is built around a few simple principles that guide every decision we make about how data is stored, accessed, and protected.

๐Ÿ”

Least-privilege access

Users should only see what they need. Role-based permissions ensure attorneys, paralegals, and intake staff each have access appropriate to their role.

๐Ÿ‘ค

Data belongs to the customer

Your firm owns its information. Lextiff and Canvas Chrome Designs do not claim ownership of customer content.

๐Ÿ“‹

Visibility and accountability

Actions inside the platform are traceable. Every status change, document upload, and case update is logged with a timestamp and user identity.

โšก

Simplicity over complexity

Security should help teams work โ€” not slow them down. Controls are designed to protect without creating friction.

๐Ÿ”„

Continuous improvement

The platform evolves and improves over time. Security is an ongoing process, not a one-time setup.

๐Ÿ›ก๏ธ

Practical transparency

We believe security should be practical and transparent โ€” not hidden behind marketing claims or borrowed certifications.

๐Ÿ”’

Encryption

Data is protected both in transit and at rest, using modern, industry-standard encryption.

  • โœ“ TLS 1.2 / 1.3 for all traffic
  • โœ“ AES-256 encryption at rest
  • โœ“ PHI field-level encryption
  • โœ“ Secure key management
  • โœ“ Server-side encryption on object storage (B2)
๐Ÿ‘ฅ

Access Controls

Control who can access what. Different members of your firm don't need the same permissions โ€” Lextiff gives you the tools to enforce that.

  • โœ“ Role-based access โ€” attorney, paralegal, intake, staff
  • โœ“ Firm-level isolation (multi-tenant)
  • โœ“ Matter-level permissions
  • โœ“ Least-privilege by default
  • โœ“ Multi-factor authentication (MFA)
  • โœ“ Session management & trusted devices
๐Ÿ”‘

Password Security

Protecting accounts starts with users. Lextiff enforces secure password practices and account management controls.

  • โœ“ Modern password hashing (bcrypt)
  • โœ“ OTP-gated password & email changes
  • โœ“ Account recovery procedures
  • โœ“ Rate-limited login attempts
  • โœ“ New-device login alerts
  • โœ“ Trusted-device recognition
๐Ÿ’พ

Backup & Availability

Data protection includes preparing for failures โ€” not just preventing them.

  • โœ“ Database backups every 15 minutes
  • โœ“ Point-in-Time Recovery (PITR)
  • โœ“ SHA-256 backup integrity verification
  • โœ“ Encrypted, versioned backups
  • โœ“ Documented Disaster Recovery Plan
  • โœ“ Restore verification checks

Ownership & Privacy

Your data remains yours.

Case information, documents, notes, messages, and uploaded files belong to your firm. Lextiff and Canvas Chrome Designs do not claim ownership of customer content โ€” and never will.

โœ“ Customer-controlled information
โœ“ Export capability available
โœ“ Account deletion requests honored
โœ“ No sale of customer data
โœ“ No advertising based on case information
โœ“ No third-party sharing without necessity

Your data belongs to you.

Every case, document, note, message, and uploaded file you enter into Lextiff is yours. We are the platform โ€” not the owner.

What we never do:

โœ— Sell customer data
โœ— Advertise using case information
โœ— Share data with unauthorized third parties
โœ— Claim ownership of uploaded content

Operational Security

How we actually run the platform.

Security isn't just controls at signup โ€” it's ongoing operational discipline.

๐Ÿšจ

Incident Response

Documented severity classification, investigation, containment, eradication, recovery, customer notification, and post-incident review.

๐Ÿ›Ÿ

Disaster Recovery

Documented recovery plan with defined recovery targets, restore verification, and scheduled recovery drills.

๐Ÿ“ก

Monitoring

Continuous monitoring of infrastructure health, authentication anomalies, application errors, and service availability.

๐Ÿ’พ

Backup Strategy

15-minute database backups, PITR, SHA-256 integrity verification, and versioned encrypted storage.

Recovery Objectives

What happens if something breaks.

These numbers demonstrate operational planning without revealing sensitive implementation details.

15 min

Database RPO

< 2 hrs

Database RTO

< 4 hrs

Application RTO

๐Ÿ”—

Third-Party Services

We rely on a small number of well-known providers, organized by function:

Infrastructure

AWS ยท Backblaze B2

Email

Resend

SMS

Twilio

Analytics

Privacy-conscious analytics tooling

Each third-party provider maintains its own privacy and security practices. Lextiff is not responsible for the security practices of third-party services.

๐Ÿšจ

Incident Response

If a security incident occurs, our team follows a documented response process:

  • โœ“ Severity classification
  • โœ“ Investigation
  • โœ“ Containment
  • โœ“ Eradication
  • โœ“ Recovery
  • โœ“ Customer notification, where required
  • โœ“ Post-incident review

Continuous monitoring

We watch the platform, so problems get caught early.

We continuously monitor our platform for:

โœ“ Infrastructure health
โœ“ Backup verification
โœ“ Integrity monitoring
โœ“ Application & audit logging
โœ“ Authentication anomalies
โœ“ Scheduled recovery testing

Responsible disclosure

Found a vulnerability?

We take security reports seriously and appreciate researchers who help us keep the platform safe. If you believe you've found a security issue, please let us know.

security@lextiff.com

Please do not publicly disclose security issues before allowing us reasonable time to investigate and respond.

Shared responsibility

Security is shared.

Lextiff provides the platform, controls, and infrastructure. Your firm is responsible for how the system is used day to day.

Lextiff is software โ€” not legal advice. Users remain solely responsible for verifying deadlines, calculations, filings, and all legal obligations applicable to their practice.

Lextiff's Responsibilities

โœ“ Platform security, encryption, and access controls
โœ“ Backups, monitoring, and disaster recovery
โœ“ Vulnerability response and patching
โœ“ Infrastructure uptime and maintenance

Customer Responsibilities

โœ“ Protecting account credentials
โœ“ Restricting access to authorized personnel
โœ“ Verifying deadlines and legal obligations
โœ“ Reporting suspected security issues promptly

Security Overview

Built with security at the core.

15 min
Backup Frequency
24/7
Monitoring
On
PITR
1.2/1.3
TLS
RBAC
Role-Based Access
Monthly
Recovery Drills

Security FAQ

Common questions from IT & security reviewers.

Trust resources

Security documents & downloads.

Lextiff is engineered with layered security controls, privacy-focused design, and modern cloud infrastructure to help law firms protect client information and operate with confidence.

Operated by Canvas Chrome Designs ยท Last security review: August 2026

Built for plaintiff attorneys who win.

Security shouldn't be complicated.

Lextiff gives firms the tools they need to organize cases, protect information, and keep teams working together โ€” all in one place.

No credit card required ยท Setup same day ยท Cancel anytime