Trust

Trust and Security

Legal teams hand us privileged and confidential material. This page says, in plain terms, what we do with it, what is in place today, what is in progress, and what is planned. Our live Trust Center lists every monitored control and is where you request documents: trust.oneleet.com/legal-operator. For anything else, email security@legaloperator.ai and we will answer directly, sign an NDA, and complete your questionnaire.

Last updated: September 2026.

Where we are on SOC 2

SOC 2 Type II: audit in progress

SOC 2 Type II: audit in progress. Our controls are being audited by an independent firm and we are in the observation period now. We expect the Type II report in November 2026. A third-party penetration test was completed in July 2026 and all findings were remediated. We can share the pen test summary and our audit timeline under NDA today, and the full report when it is issued.

In place today

What is in place today

Every line below is live.

AI and your data

How AI handles your data

Subprocessors

Who else touches your data

We notify customers before adding or changing a subprocessor.

Subprocessor Purpose Data handled
OpenAI AI answers and search embeddings Prompts and generated answers; not used for training; DPA in place
DigitalOcean Hosting, managed database, background workers, file storage (US West) Customer application data and uploaded files at rest
PostHog Product analytics Usage metadata only; content excluded
Customer-connected sources (optional) Knowledge import and chat channels, only when you connect them Only the data you choose to connect: Google Drive, SharePoint, Notion, Slack, Teams, Zoom Chat, Jira

See every live connection on our Integrations page.

Planned

What is planned

Stated so reviewers can see the direction. Dates appear only where we have committed to one.

Common questions

Is LegalOperator SOC 2 certified?

Not yet. Our SOC 2 Type II audit is in progress with an independent firm, we are in the observation period, and we expect the report in November 2026. A third-party penetration test was completed in July 2026 with all findings remediated. We share the pen test summary and audit timeline under NDA and will post the report on our Trust Center when issued.

Does LegalOperator use my data to train AI?

No. Customer data is never used to train our models or OpenAI's models. Our privacy policy states it and our Data Processing Addendum with OpenAI prohibits it. Iris and the front door answer only from your own uploaded policies, playbooks and approved answers, never from the open internet.

Where is my data stored and who can see it?

Data is hosted on DigitalOcean in the US West region, encrypted in transit and at rest, and isolated per customer at the data layer. Inside your workspace, role-based access and sealed restricted matters control who sees what. Our staff access is limited to the founders, for support only.

Can I delete my data?

Yes. On request we fully delete a customer: files are removed from storage and a hard delete is cascaded through every related table. Retention during your subscription follows your own configuration, and data is deleted or returned at termination under our DPA.

Will you complete our security questionnaire and sign a DPA?

Yes to both. Email security@legaloperator.ai. We answer questionnaires directly, sign NDAs, provide our DPA, and share the penetration test summary and SOC 2 timeline. Our live Trust Center at trust.oneleet.com/legal-operator lists every monitored control.

Security questions? Ask us directly.

Questionnaires, NDAs, the DPA, the pen test summary and the SOC 2 timeline. One email, a direct answer.

Email security@legaloperator.ai Open the Trust Center ›