Security built for law firms.
Protecting case information isn't a feature. It's the foundation.
Lextiff is designed with practical security principles to help plaintiff firms organize, manage, and protect their data. Every account, case, document, and workflow is built with security in mind.
Compliance
What's in place today โ and what's next.
We only list what we've actually implemented. No badges we don't own.
Current
Roadmap
Lextiff is designed to support these standards โ this page describes our architecture and practices, and does not constitute a certification. Formal certifications, where pursued, will be announced separately.
Infrastructure
Where your data lives.
We know firms want to understand the infrastructure behind the platform, not just take security claims on faith.
Secure cloud infrastructure
Multi-region backups
Continuous monitoring
Disaster recovery planning
Secure object storage
TLS encryption
High availability architecture
Redundant systems
Our approach
Security by Design.
Lextiff is built around a few simple principles that guide every decision we make about how data is stored, accessed, and protected.
Least-privilege access
Users should only see what they need. Role-based permissions ensure attorneys, paralegals, and intake staff each have access appropriate to their role.
Data belongs to the customer
Your firm owns its information. Lextiff and Canvas Chrome Designs do not claim ownership of customer content.
Visibility and accountability
Actions inside the platform are traceable. Every status change, document upload, and case update is logged with a timestamp and user identity.
Simplicity over complexity
Security should help teams work โ not slow them down. Controls are designed to protect without creating friction.
Continuous improvement
The platform evolves and improves over time. Security is an ongoing process, not a one-time setup.
Practical transparency
We believe security should be practical and transparent โ not hidden behind marketing claims or borrowed certifications.
Encryption
Data is protected both in transit and at rest, using modern, industry-standard encryption.
- โ TLS 1.2 / 1.3 for all traffic
- โ AES-256 encryption at rest
- โ PHI field-level encryption
- โ Secure key management
- โ Server-side encryption on object storage (B2)
Access Controls
Control who can access what. Different members of your firm don't need the same permissions โ Lextiff gives you the tools to enforce that.
- โ Role-based access โ attorney, paralegal, intake, staff
- โ Firm-level isolation (multi-tenant)
- โ Matter-level permissions
- โ Least-privilege by default
- โ Multi-factor authentication (MFA)
- โ Session management & trusted devices
Password Security
Protecting accounts starts with users. Lextiff enforces secure password practices and account management controls.
- โ Modern password hashing (bcrypt)
- โ OTP-gated password & email changes
- โ Account recovery procedures
- โ Rate-limited login attempts
- โ New-device login alerts
- โ Trusted-device recognition
Backup & Availability
Data protection includes preparing for failures โ not just preventing them.
- โ Database backups every 15 minutes
- โ Point-in-Time Recovery (PITR)
- โ SHA-256 backup integrity verification
- โ Encrypted, versioned backups
- โ Documented Disaster Recovery Plan
- โ Restore verification checks
Ownership & Privacy
Your data remains yours.
Case information, documents, notes, messages, and uploaded files belong to your firm. Lextiff and Canvas Chrome Designs do not claim ownership of customer content โ and never will.
Your data belongs to you.
Every case, document, note, message, and uploaded file you enter into Lextiff is yours. We are the platform โ not the owner.
What we never do:
Operational Security
How we actually run the platform.
Security isn't just controls at signup โ it's ongoing operational discipline.
Incident Response
Documented severity classification, investigation, containment, eradication, recovery, customer notification, and post-incident review.
Disaster Recovery
Documented recovery plan with defined recovery targets, restore verification, and scheduled recovery drills.
Monitoring
Continuous monitoring of infrastructure health, authentication anomalies, application errors, and service availability.
Backup Strategy
15-minute database backups, PITR, SHA-256 integrity verification, and versioned encrypted storage.
Recovery Objectives
What happens if something breaks.
These numbers demonstrate operational planning without revealing sensitive implementation details.
Database RPO
Database RTO
Application RTO
Third-Party Services
We rely on a small number of well-known providers, organized by function:
Infrastructure
AWS ยท Backblaze B2
Resend
SMS
Twilio
Analytics
Privacy-conscious analytics tooling
Each third-party provider maintains its own privacy and security practices. Lextiff is not responsible for the security practices of third-party services.
Incident Response
If a security incident occurs, our team follows a documented response process:
- โ Severity classification
- โ Investigation
- โ Containment
- โ Eradication
- โ Recovery
- โ Customer notification, where required
- โ Post-incident review
Continuous monitoring
We watch the platform, so problems get caught early.
We continuously monitor our platform for:
Responsible disclosure
Found a vulnerability?
We take security reports seriously and appreciate researchers who help us keep the platform safe. If you believe you've found a security issue, please let us know.
security@lextiff.comPlease do not publicly disclose security issues before allowing us reasonable time to investigate and respond.
Shared responsibility
Security is shared.
Lextiff provides the platform, controls, and infrastructure. Your firm is responsible for how the system is used day to day.
Lextiff is software โ not legal advice. Users remain solely responsible for verifying deadlines, calculations, filings, and all legal obligations applicable to their practice.
Lextiff's Responsibilities
Customer Responsibilities
Security Overview
Built with security at the core.
Security FAQ
Common questions from IT & security reviewers.
Trust resources
Security documents & downloads.
Lextiff is engineered with layered security controls, privacy-focused design, and modern cloud infrastructure to help law firms protect client information and operate with confidence.
Operated by Canvas Chrome Designs ยท Last security review: August 2026
Built for plaintiff attorneys who win.
Security shouldn't be complicated.
Lextiff gives firms the tools they need to organize cases, protect information, and keep teams working together โ all in one place.
No credit card required ยท Setup same day ยท Cancel anytime