Skip to content
EdgeLex

Security, privacy & AI governance

Built so your firm keeps control.

EdgeLex is the authority layer. Your firm owns identity, permissions, data, and the audit trail. The AI works under your policy — never around it.

Book a Demo

Shown, not claimed

Watched. Scored. Explained. Caught. Advised. Proven.

Security pages are usually a list of promises. Here is the actual monitoring system — every screen below is the real product.

01 · Watched

Every action in the firm is a log line with a risk score.

1,074 activities in the last 24 hours — document access, matter access, admin actions — distributed, scored, and summarized: failed attempts, after-hours percentage, average risk, unique access locations. The audit trail isn't a feature you enable for litigation; it's the always-on nervous system.

app.edgelex.com — Admin · User Logging SystemMC

User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts

OverviewUser Activities99+Security EventsSecurity Alerts99+ReportsSettings

System Health● healthy

🗄 DatabaseConnected · Last Activity 6:01 PMQueue ProcessingActive Jobs: 0 · Real-timeSecurity AlertsActive: 1,306 · Require Attention
1,074

Total Activities · last 24h

4

Active Users · unique

0

High Risk · score ≥ 70

32

Security Events · failed attempts

Activity Distribution

document access43940.9%

matter access27125.2%

admin access23622.0%

document version363.4%

client access333.1%

32

Failed Attempts

4xx/5xx errors

17%

After Hours

Outside 6am–10pm

6.36

Avg Risk Score

Out of 100

4

Access Locations

Unique IPs

02 · Scored

The live feed is the audit trail.

Who did what, from where, at what risk — streaming as it happens, with filters and export. Normal activity reads as normal; the system says "no concerns" only because it actually checked.

app.edgelex.com — Admin · User Logging — Live User ActivitiesMC

User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts

OverviewUser Activities99+Security EventsSecurity Alerts99+ReportsSettings

⚡ Live User ActivitiesLive Updates▽ Filters⟳ Refresh⬇ Export

TimeUserActivityRiskIP Address
8/15
6:01 PM
Maya Chen Attorney
maya@chenokafor.com
Accessed documents
document_management
● Low Risk
Normal activity, no concerns
10.24.8.14👁 View
8/15
6:01 PM
Maya Chen Attorney
maya@chenokafor.com
Performed administrative action
admin_management
● Low Risk
Normal activity, no concerns
10.24.8.14👁 View
8/15
5:58 PM
Maya Chen Attorney
maya@chenokafor.com
Accessed user management
admin_management
● Low Risk
Normal activity, no concerns
10.24.8.14👁 View
8/15
5:52 PM
Maya Chen Attorney
maya@chenokafor.com
Opened matter workspace
matter_access
● Low Risk
Normal activity, no concerns
10.24.8.14👁 View

Every action, every user, scored in real time — document opens, admin actions, matter access, version pulls. The feed is the audit trail, live.

03 · Explained

Every log line can explain itself.

Open any event and the forensics are complete: the user's classification and access level, the exact endpoint called, the full request metadata — and Lex standing by to explain what the event means in plain language. An audit entry you can interrogate beats a million rows nobody reads.

app.edgelex.com — Admin · Activity DetailsMC

Activity Details✦ Lex

Timestamp

8/15/2026, 6:01:37 PM

Maya ChenAttorney

maya@chenokafor.com · ID: 7d31c92e-4b05-41f8-a2c6-9e8b5a3f01d4

Classification: Attorney · Role: Attorney · Access Level: Medium · 🏢 Chen & Okafor LLP

Activity Type

document_access

Risk Score

● 5

IP Address

10.24.8.14

Category

document_management

Endpoint

GET /c4f8a17e-…/checkout-status

Metadata

{
  “method”: “GET”,
  “dmsRole”: “Attorney”,
  “endpoint”: “/api/v1/dms/documents/…/checkout-status”,
  “isAttorney”: true, “document_id”: “c4f8a17e-…”
}

Lex Explanation

Lex is analyzing this…

Close

04 · Caught

When something is wrong, it says so — loudly.

A privilege-escalation attempt turns the posture banner red and the word is CRITICAL, not "advisory." Bulk data access, repeated forbidden access, escalation attempts — detected, classified by severity, and held open until a human closes them. A security dashboard that can't alarm you can't protect you.

app.edgelex.com — Admin · Security Events DashboardMC

User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts

OverviewUser Activities99+Security EventsSecurity Alerts99+ReportsSettings

Security Events DashboardReal-time security monitoring and analysisLast 7 Days ▾✦ Lex⟳ Refresh

⚠ 🛡 SECURITY POSTURE: CRITICAL87/100Security Score

4,429 Activities Analyzed · Last Scan: 6:01:37 PM

4,429

Total Events

4

Categories Secure

1

Need Attention

0

Critical Issues

⚡ Recent Security EventsDetected anomalies and incidents107 total

8/15 5:47 PMcriticalprivilege_escalation_attempt203.0.113.67openⓘ View
8/15 5:41 PMhighbulk_data_access10.24.8.14openⓘ View
8/15 5:03 PMhighrepeated_forbidden_access203.0.113.67openⓘ View
8/15 5:03 PMcriticalprivilege_escalation_attempt203.0.113.67openⓘ View
8/15 12:20 PMhighbulk_data_access10.24.8.14openⓘ View

05 · Advised

Anomalies come with a recommendation, not just a graph.

Activity 4x above a user's own baseline, logins from five IP addresses — each anomaly arrives as a prioritized recommendation in plain English, with the evidence attached. The system compares users to themselves, which is the comparison that catches compromised accounts.

app.edgelex.com — Admin · Security AlertsMC

User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts

OverviewUser Activities99+Security EventsSecurity Alerts99+ReportsSettings
⚡ Security Activity Summary
66Total Events22Critical Events0High Risk2Active Threats
◎ Security Recommendations

Suggested improvements for your security posture

Unusual Activity Volume Detected

User activity is 4x higher than normal (3 vs avg 1). Possible account compromise or automated activity.

high Priority

Unusual Activity Volume Detected

User activity is 6x higher than normal (37 vs avg 7). Possible account compromise or automated activity.

high Priority

Multiple Access Locations Detected

User accessed from 5 different IP addresses: 10.24.8.14, 203.0.113.65, 10.24.8.79… Verify these are legitimate access points.

medium Priority

06 · Proven

The same logs become the compliance record.

Monthly compliance and weekly security reports on a schedule, or any window on demand — generated from the same log store that drives the live dashboards. When the questionnaire asks how you'd know about unauthorized access, the answer is a report, not a shrug.

app.edgelex.com — Admin · Compliance ReportsMC

User Logging SystemSystem healthyLive Updates100Recent Activities0Security Events1,306Active Alerts

OverviewUser Activities99+Security EventsSecurity Alerts99+ReportsSettings
📄 Quick Templates

Monthly Compliance

Weekly Security

✓ Report Statistics

Total Generated: 12
This Month: 3
Available: 12

⚙ Scheduled Reports

Auto-generate: Enabled
Next run: Sep 1, 6:00 AM

🗓 Configure

Generate New Report

Report Type

Compliance Summary ▾

Start Date

07/16/2026 🗓

End Date

08/15/2026 🗓

Include in Report: User Activities   Security Events

📄 Generate Report

The same logs that drive the live dashboards export as compliance and audit reports — monthly compliance and weekly security on a schedule, or any window on demand.

Data sovereignty

  • Deploy in EdgeLex's cloud, your private cloud, or fully self-hosted — your choice.
  • Wherever it runs, your data stays under your firm's governance; self-host to keep it entirely in your own infrastructure.
  • No mandatory third-party access to case data.
  • Per-firm isolation: each firm is a separate identity realm, with queries scoped per firm at the data layer — no cross-tenant bleed.

AI governance

  • Three-layer model policy (platform → firm → user) with default-deny: no model runs unless explicitly allowed.
  • Local or frontier models — the firm chooses; bring-your-own-key with encrypted credential storage.
  • Mutation safety: a routing layer blocks underpowered models from destructive actions (send, delete, file, approve).
  • Evidence grounding: answers must be grounded in your data and cite sources; ungrounded answers are blocked.
  • Approval gates on high-impact actions.
  • Full cost & token attribution by firm, user, model, and matter — no opaque AI spend.

Access & identity

  • Standard identity provider (OpenID Connect) with per-firm realms.
  • Role-based access control; configurable session limits and timeouts.
  • Optional IP binding; MFA gating for sensitive actions like signing.

Encryption & credentials

  • Sensitive credentials encrypted with AES-256-GCM (authenticated encryption), with per-credential IVs.
  • Firms can hold their own keys (BYOK).

Audit & accountability

  • Comprehensive activity, security-event, and AI-decision logging in a dedicated log store.
  • Before / after state on writes; correlation IDs throughout.
  • Signature evidence chains and document freeze-on-signature.

Compliance posture

EdgeLex provides the controls firms need to support their SOC 2, GDPR, and ABA-aligned obligations: data residency, encryption, granular access control, comprehensive audit logging, and legal-hold and retention features. Self-hosting means your data-handling stays under your governance.

EdgeLex provides controls designed to support these frameworks; it does not itself hold these certifications.

EdgeLex vs. black-box cloud legal AI

An honest, dimension-by-dimension comparison.

Compared against the category of cloud legal AI on dimensions you can verify — not a characterization of any one product. Where a specific vendor offers a private deployment, that's to their credit.

DimensionEdgeLexTypical cloud legal AI
Self-hosting option YesVaries
Data locality (firm-controlled) YesVaries
Model choice (local + frontier) YesVaries
Per-firm isolation YesVaries
AI governance policy (default-deny) YesVaries
Audit & cost attribution YesVaries
Evidence-grounded answers YesVaries

Bring your security questionnaire.

We'll walk your team through the architecture, the audit model, and self-hosting.