Security and trust

Security is a shared responsibility

LexLINQ applies technical and organisational safeguards to reduce security risks, while users remain responsible for safe account, device, and content handling.

Last updated: 5 August 2026

No online system can be guaranteed completely secure. This page describes LexLINQ’s security approach without representing that every risk can be eliminated or that the service holds a certification not expressly stated here.

1. Our security approach

LexLINQ uses layered technical and organisational measures intended to protect accounts and Customer Content against unauthorised access, alteration, disclosure, or loss. Controls are reviewed as the product and risks change.

Security information can become outdated as systems and providers change. Organisations conducting vendor due diligence should contact us for current information relevant to their assessment.

2. Accounts and access

  • Access to the service requires an authenticated account.
  • Matter and document requests are evaluated in the context of the authenticated user and applicable permissions.
  • Users must keep credentials confidential, use unique passwords, secure their devices, and promptly report suspected account compromise.
  • Customers are responsible for granting, reviewing, and removing access for their personnel.

3. Matter and document boundaries

Matter AI is designed to work from completed, indexed documents available within the current matter workspace. Users must not attempt to retrieve another customer’s or user’s information, bypass access controls, or use prompt injection or similar techniques to alter system safeguards.

A generated answer is not evidence that a user is authorised to access or disclose the underlying material. Customers must independently maintain appropriate matter access and confidentiality procedures.

4. Service providers and AI processing

LexLINQ uses service providers for functions such as hosting, storage, payments, communications, and AI processing. Depending on the feature and configuration, AI processing may involve API services supplied by OpenAI, Google Gemini, or Anthropic.

We assess service providers and apply contractual, configuration, and access measures appropriate to the service. Provider infrastructure, subprocessors, and processing locations may change. See the Privacy Policy for more detail.

5. Operational safeguards

  • Changes are subject to development and review processes appropriate to their risk.
  • Application and operational records are used to support troubleshooting, security review, billing integrity, and incident investigation.
  • Access to production systems and customer information is limited to authorised purposes and personnel.
  • Backups, recovery arrangements, monitoring, and provider controls form part of the wider service resilience approach.

6. Customer responsibilities

  • Upload only content you are authorised to use and process.
  • Do not include personal, sensitive, confidential, or privileged information unless its use is necessary, authorised, and permitted by professional and legal obligations.
  • Review exports, downloads, shared links, and generated content before disclosing them.
  • Use current devices and browsers, apply security updates, and maintain appropriate endpoint and network controls.

7. Reporting a security concern

Report a suspected vulnerability, privacy incident, or unauthorised account activity to info@lexlinq.ai. Include enough detail for us to investigate, but do not send unnecessary confidential material by ordinary email.

We investigate reported concerns and manage eligible data breaches in accordance with applicable Australian law.

FAQ

Common questions

Is any online service completely secure?

No. LexLINQ applies safeguards intended to reduce risk, but no online system or transmission method can guarantee absolute security.

Where should a security concern be reported?

Email info@lexlinq.ai with the relevant details and avoid including unnecessary confidential material.