Security, privacy & AI governance
Built so your firm keeps control.
EdgeLex is the authority layer. Your firm owns identity, permissions, data, and the audit trail. The AI works under your policy — never around it.
Shown, not claimed
Watched. Scored. Explained. Caught. Advised. Proven.
Security pages are usually a list of promises. Here is the actual monitoring system — every screen below is the real product.
01 · Watched
Every action in the firm is a log line with a risk score.
1,074 activities in the last 24 hours — document access, matter access, admin actions — distributed, scored, and summarized: failed attempts, after-hours percentage, average risk, unique access locations. The audit trail isn't a feature you enable for litigation; it's the always-on nervous system.
User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts
System Health● healthy
Total Activities · last 24h
Active Users · unique
High Risk · score ≥ 70
Security Events · failed attempts
document access43940.9%
matter access27125.2%
admin access23622.0%
document version363.4%
client access333.1%
Failed Attempts
4xx/5xx errors
After Hours
Outside 6am–10pm
Avg Risk Score
Out of 100
Access Locations
Unique IPs
02 · Scored
The live feed is the audit trail.
Who did what, from where, at what risk — streaming as it happens, with filters and export. Normal activity reads as normal; the system says "no concerns" only because it actually checked.
User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts
⚡ Live User ActivitiesLive Updates▽ Filters⟳ Refresh⬇ Export
6:01 PMMaya Chen Attorney
maya@chenokafor.comAccessed documents
document_management● Low Risk
Normal activity, no concerns10.24.8.14👁 View
6:01 PMMaya Chen Attorney
maya@chenokafor.comPerformed administrative action
admin_management● Low Risk
Normal activity, no concerns10.24.8.14👁 View
5:58 PMMaya Chen Attorney
maya@chenokafor.comAccessed user management
admin_management● Low Risk
Normal activity, no concerns10.24.8.14👁 View
5:52 PMMaya Chen Attorney
maya@chenokafor.comOpened matter workspace
matter_access● Low Risk
Normal activity, no concerns10.24.8.14👁 View
Every action, every user, scored in real time — document opens, admin actions, matter access, version pulls. The feed is the audit trail, live.
03 · Explained
Every log line can explain itself.
Open any event and the forensics are complete: the user's classification and access level, the exact endpoint called, the full request metadata — and Lex standing by to explain what the event means in plain language. An audit entry you can interrogate beats a million rows nobody reads.
Activity Details✦ Lex
Timestamp
8/15/2026, 6:01:37 PM
Maya ChenAttorney
maya@chenokafor.com · ID: 7d31c92e-4b05-41f8-a2c6-9e8b5a3f01d4
Classification: Attorney · Role: Attorney · Access Level: Medium · 🏢 Chen & Okafor LLP
Activity Type
document_accessRisk Score
● 5IP Address
10.24.8.14Category
document_managementEndpoint
GET /c4f8a17e-…/checkout-status
Metadata
{
“method”: “GET”,
“dmsRole”: “Attorney”,
“endpoint”: “/api/v1/dms/documents/…/checkout-status”,
“isAttorney”: true, “document_id”: “c4f8a17e-…”
}
Lex Explanation
Lex is analyzing this…
Close
04 · Caught
When something is wrong, it says so — loudly.
A privilege-escalation attempt turns the posture banner red and the word is CRITICAL, not "advisory." Bulk data access, repeated forbidden access, escalation attempts — detected, classified by severity, and held open until a human closes them. A security dashboard that can't alarm you can't protect you.
User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts
Security Events DashboardReal-time security monitoring and analysisLast 7 Days ▾✦ Lex⟳ Refresh
⚠ 🛡 SECURITY POSTURE: CRITICAL87/100Security Score
4,429 Activities Analyzed · Last Scan: 6:01:37 PM
Total Events
Categories Secure
Need Attention
Critical Issues
⚡ Recent Security EventsDetected anomalies and incidents107 total
05 · Advised
Anomalies come with a recommendation, not just a graph.
Activity 4x above a user's own baseline, logins from five IP addresses — each anomaly arrives as a prioritized recommendation in plain English, with the evidence attached. The system compares users to themselves, which is the comparison that catches compromised accounts.
User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts
Suggested improvements for your security posture
ⓘ Unusual Activity Volume Detected
User activity is 4x higher than normal (3 vs avg 1). Possible account compromise or automated activity.
high Priority
ⓘ Unusual Activity Volume Detected
User activity is 6x higher than normal (37 vs avg 7). Possible account compromise or automated activity.
high Priority
ⓘ Multiple Access Locations Detected
User accessed from 5 different IP addresses: 10.24.8.14, 203.0.113.65, 10.24.8.79… Verify these are legitimate access points.
medium Priority
06 · Proven
The same logs become the compliance record.
Monthly compliance and weekly security reports on a schedule, or any window on demand — generated from the same log store that drives the live dashboards. When the questionnaire asks how you'd know about unauthorized access, the answer is a report, not a shrug.
User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts
Monthly Compliance
Weekly Security
Total Generated: 12
This Month: 3
Available: 12
Auto-generate: Enabled
Next run: Sep 1, 6:00 AM
🗓 Configure
Report Type
Compliance Summary ▾Start Date
07/16/2026 🗓End Date
08/15/2026 🗓Include in Report: ☑ User Activities ☑ Security Events
📄 Generate Report
The same logs that drive the live dashboards export as compliance and audit reports — monthly compliance and weekly security on a schedule, or any window on demand.
Data sovereignty
- Deploy in EdgeLex's cloud, your private cloud, or fully self-hosted — your choice.
- Wherever it runs, your data stays under your firm's governance; self-host to keep it entirely in your own infrastructure.
- No mandatory third-party access to case data.
- Per-firm isolation: each firm is a separate identity realm, with queries scoped per firm at the data layer — no cross-tenant bleed.
AI governance
- Three-layer model policy (platform → firm → user) with default-deny: no model runs unless explicitly allowed.
- Local or frontier models — the firm chooses; bring-your-own-key with encrypted credential storage.
- Mutation safety: a routing layer blocks underpowered models from destructive actions (send, delete, file, approve).
- Evidence grounding: answers must be grounded in your data and cite sources; ungrounded answers are blocked.
- Approval gates on high-impact actions.
- Full cost & token attribution by firm, user, model, and matter — no opaque AI spend.
Access & identity
- Standard identity provider (OpenID Connect) with per-firm realms.
- Role-based access control; configurable session limits and timeouts.
- Optional IP binding; MFA gating for sensitive actions like signing.
Encryption & credentials
- Sensitive credentials encrypted with AES-256-GCM (authenticated encryption), with per-credential IVs.
- Firms can hold their own keys (BYOK).
Audit & accountability
- Comprehensive activity, security-event, and AI-decision logging in a dedicated log store.
- Before / after state on writes; correlation IDs throughout.
- Signature evidence chains and document freeze-on-signature.
Compliance posture
EdgeLex provides the controls firms need to support their SOC 2, GDPR, and ABA-aligned obligations: data residency, encryption, granular access control, comprehensive audit logging, and legal-hold and retention features. Self-hosting means your data-handling stays under your governance.
EdgeLex provides controls designed to support these frameworks; it does not itself hold these certifications.
EdgeLex vs. black-box cloud legal AI
An honest, dimension-by-dimension comparison.
Compared against the category of cloud legal AI on dimensions you can verify — not a characterization of any one product. Where a specific vendor offers a private deployment, that's to their credit.
| Dimension | EdgeLex | Typical cloud legal AI |
|---|---|---|
| Self-hosting option | Yes | Varies |
| Data locality (firm-controlled) | Yes | Varies |
| Model choice (local + frontier) | Yes | Varies |
| Per-firm isolation | Yes | Varies |
| AI governance policy (default-deny) | Yes | Varies |
| Audit & cost attribution | Yes | Varies |
| Evidence-grounded answers | Yes | Varies |
Bring your security questionnaire.
We'll walk your team through the architecture, the audit model, and self-hosting.