IT Security Measures

Applicable from 1 September 2026

A.4 Risk management
A.5 Information security policy
A.6 Organisation of information security
A.7 Human resource security
A.8 Asset management
A.9 Access management
A.10 Cryptography
A.11 Physical and environment security
A.12 Operations security
A.13 Communications security
A.14 Procurement, development, and maintenance of systems
A.15 Supplier conditions
A.16 Management of information security and personal data breaches
A.18 Compliance


The following describes .legals technical and organisational security measures for the Services. In addition, an audit statement, ISAE-3402 or equivalent, is prepared annually and can be downloaded here.

A.4 Risk management 

Annual risk assessment 

The Executive Board of .legal A/S conducts a risk assessment at least once a year, which includes the IT installations and their use. It is based on the current threat picture and new knowledge in the field, which forms the basis for new security initiatives.

Guidelines and control objectives 

Internally, we have documented several control objectives to ensure that we comply with our security policy.   

The control objectives include: 

A. Purpose: Describes why the control objective is established and ensure that it reflects the overall guideline for the ISO section. 

B. Measurement point: Describes how the control objective is to be assessed, so that a satisfactory data basis is established, and so that the measurement can be carried out within the time interval described, which ensures that the objective is specific and measurable. 

C. Threshold: Shows what is required to meet the control objective. 

The .legal Compliance Platform is used for follow-up and documentation of the internal control objectives.

A.5 Information security policies

IT security policy  

.legal works according to an IT security policy that covers the Services. The IT security policy is organised according to ISO 27001: 2013 and forms the basis for those involved in the development or operation of the Services. The IT security policy is organised according to the standardised ISO areas. 

The follow-up on whether the requirements are complied with is in accordance with several guidelines and control objectives, which are described in the policy for each ISO area.

The IT security policy has been approved by Management and published in the Company, including communication to relevant employees and partners. To ensure that the IT security policy is appropriate, adequate, and effective, the IT security policy is reassessed at least once a year or in the event of extensive changes in the organisation that have an impact on the information security.

A.6 Organisation of information security 

IT security manager 

.legal A/S has dedicated an employee with responsibility for organisational and system security. 

Segregation of duties 

.legal A/S works with segregation of duties to ensure that employees only have access to information required to perform their duties and functions. We work with the functions “Bookkeeping, HR, Legal & Compliance, Marketing, Project Management, Sales, Support, Development and UX & Design”.  

We review the employees’ access regularly to ensure that the accesses continue to match their duties. 

A.7 Human resource security​

Confidentiality 

As part of the employment, all employees/consultants have entered a duty of confidentiality which ensures that confidential information is not passed on. The duty of confidentiality applies both during and after employment. In addition, the relevant employees sign a declaration of compliance with the IT Security Policy, which further ensures that information about the system and its security conditions, employees, trade secrets, and information about business relationships remain confidential.

A.8 Asset management 

Inventory of assets 

All the assets of the systems have been identified and a list of the assets has been prepared. The list of assets is documented and contains relevant descriptions of sub-components, physical and logical location as well as ownership. 

A.9 Access control

Principles of access control  

Access to the systems is always allocated based on the "need-to-know" / "need-to-have" and "least privilege" principles, so that it is ensured that access is allocated to users with work-related needs. 

Secure login with two-factor authentication  

There are several options for system access, depending on the system. The options range from a single sign-on solution via integration with the customer's Microsoft Azure Active Directory to standard email/password authentication or via .legal ID.  

.legal ID is a proprietary login provider based on the OpenID Connect / OAuth2.0 security protocols and allows the user to use their .legal ID across .legal products. In addition, .legal ID also supports 2-factor authentication. 

Brute force protection  

Our login provider is protected against brute force attacks by blocking the user after three login attempts.

The password requirements are: 

  • Must contain at least 12 characters
  • Must contain at least 5 different characters
  • Must combine uppercase and lowercase letters, numbers, and symbols
  • Must not contain the username
  • May not be too common (We check against OWASP's SecLists Project of 10,000 most used passwords)

Roles and rights management 

Access to functionality in the systems is controlled via a role-based model, where a user is assigned several roles that provide access to specific parts or functions in the system. In systems where there is a need, the rights can be further granulated in relation to reading and writing access. 

Privileged access management 

An employee with a need for access to production data or production infrastructure (privileged access) must, in addition to a work-related need, have separate approval from the Executive Board. Employees with privileged access must always use 2-factor authentication. Employees with priviliged access is minimized to an absolute minimum.

Customer Lockbox for Microsoft Azure

Most operations, support, and troubleshooting performed by Microsoft personnel and sub-processors do not require access to customer data. In those rare circumstances where such access is required, Customer Lockbox for Microsoft Azure provides an interface for customers to review and approve or reject customer data access requests. It is used in cases where a Microsoft engineer needs to access customer data, whether in response to a customer-initiated support ticket or a problem identified by Microsoft.

Customer Lockbox is enabled for all .legal Microsoft Azure Tenants.
 

A.10 Cryptography

Encryption 

The system is a pure browser-based solution. The system encrypts all communication between the client (browser) and the server.

The system uses a SHA-2 SSL certificate with a minimum of 2048bit encryption from a trusted provider.

A minimum of TLS 1.2 is required for all requests to the system.
 

Data is encrypted "at rest" when stored in the data center and automatically decrypted when accessed. This is done using AES-256 encryption. Encryption keys are managed automatically with regular rotation.

A.11 Physical and environmental security

Physical security of premises and machines 

.legal A/S’ premises are locked at all times. .legal A/S does not host solutions itself, which means that the physical security primarily concerns the employees' machines. All employees' machines are encrypted. 

Physical access management

Physical access to the office premises is restricted to employees with a work-related need. Access rights are revoked immediately when an employee leaves .legal A/S as part of the offboarding process. On a quarterly basis, .legal A/S reviews the list of users with physical access to the office premises to ensure that access rights remain appropriate and that any unauthorised access is identified in a timely manner.

A.12 Operations security 

Secure hosting  

Microsoft Azure is the overall IT platform for the systems in .legal A/S. 

A. The code is stored and managed in Azure DevOps. 

B. Data is stored in Azure Storage and Azure SQL European data centres. 

C. Test and operating environments for the applications are also established in Azure. 

The systems are hosted in Microsoft Azure - i.a. for security reasons, as the underlying platform, is always up-to-date, and the possibilities for data encryption, redundancy, backup and access control are generally good. 

Concerning the use of third-party services outside Azure, these are selected based on requirements for a high-security standard (eg ISO27001 certification) as well as compliance with the GDPR. In general, we try to reduce the need of third-party services outside of Microsoft Azure.

AI-based features

AI-based features are not part of the standard Services and are only available if the customer actively opts in to the AI add-on, which is governed by .legal's AI Terms, available here.

The AI-based features are provided through a vetted sub-processor. Data is processed within the EU, and Zero Data Retention (ZDR) is enabled, meaning that input and output data are not retained or used for model training, neither by .legal nor by the sub-processor.

The AI-based features are designed to support the user's own work. They do not make independent decisions, and AI output is intended to be reviewed by the user before it is relied upon.

.legal has assessed the AI-based features in the Services against the requirements of the AI Act, including their risk classification. Based on this assessment, the current features are not considered high-risk AI systems.

Data redundancy   

Production databases are actively geo-replicated to secondary databases located in Nothern Europe. If a primary database is down, this allows for fast failover to the corresponding secondary database which help to ensure high availability of the systems.

Customer documents are stored in read-access geo-redundant storage: three synchronous copies in West Europe and three further copies replicated to North Europe.

Database backup within Azure 

Continuous backup allows the database to be restored to any point in time within the last 30 days.

Weekly full backups are retained for a further two months in immutable storage that cannot be altered or deleted, including by .legal's own personnel.

Database backups are stored in geo-redundant storage: three copies within West Europe and three further copies in North Europe. This applies both to the continuous point-in-time backup and to the weekly full backups.

Database backups are held in storage managed by Microsoft and are not reachable from .legal's environment or with .legal's credentials.

All database backups are written with checksum verification, and integrity is verified during both backup and restore.

Document backup within Azure

Documents are versioned, so earlier versions remain available after a document is changed or overwritten.

A deleted document can be restored for 30 days after deletion, and permanent deletion within that period is blocked at platform level.

Each customers document storage can be restored as a whole to any point in time within the last 30 days.

Document storage is geo-redundant, as described under Data redundancy above.

Backup outside Azure

In addition to the backup within Azure, a copy of production databases and document files is transferred every night to object storage at an independent provider, Hetzner, so that the data is also held outside Microsoft Azure and protected against provider-level incidents. The provider is listed in .legal's overview of data processors.

Hetzner is a European company, wholly owned and operated within the EU, and the data is stored in Germany. The backup is therefore held both outside Microsoft Azure and outside the ownership of any non-EU group.

Both the database backup files and the file contents are encrypted with AES-256 before they leave Azure. The encryption keys are held by .legal outside Microsoft Azure and are not available to the storage provider, which therefore holds only encrypted data.

The nightly backup is retained for 30 days on immutable storage that cannot be altered or deleted during that period, which protects it against ransomware and against accidental or malicious deletion.

Network Security

Documents and database records never traverse the public internet within our infrastructure. All connections between our application and storage systems occur through isolated private networks (VNet) with strict firewall rules.

Passwordless Storage and Database Access

Database and document storage use managed identity authentication instead of passwords or keys. This means:

  • No database passwords or secrets are stored in configuration files
  • Automatic credential rotation without downtime

Automated Threat Detection

All uploaded documents undergo automatic malware scanning before storage. Files are checked against continuously updated threat databases, with infected documents automatically quarantined.

Vulnerability management

All third-party software dependencies are scanned for known vulnerabilities on every build and nightly. Findings from the scan alert the relevant team automatically.

Vulnerabilities are remediated within the following timeframes: Critical within 3 days, High within 30 days, Moderate within 90 days and Low within 180 days.

Logging, Monitoring and Alerts  

System events are logged to a central system log, so it is possible to track any errors across components in the overall system. The overall system is monitored via Dashboards, where we can follow resource consumption, usage, and errors in an overall overview. Based on the centralised log, several alarms have been defined that are handled by the development team. 

Changes to data and configuration in the Services are recorded in an audit log, which is available to the customer's administrators within the Services.

Authentication and access events, including logins and access to records, are logged centrally. These logs are retained for 180 days. Logs are deleted automatically when the retention period expires.

Access to logs is restricted to personnel with privileged access, as described under A.9. Logs contain only the information necessary for security monitoring and incident investigation, such as user identity, timestamp and action performed.

High availability  

We strive to keep all our services available 24 hours a day, 365 days a year. We continually release new features and enhancements, but all services are released automatically and most without downtime. If a service cannot be released without downtime, we schedule the change according to usage so that as few users as possible are affected. If we know the change will affect users, the customer is notified in advance. 

All our services are hosted on Azure with the following service level agreement (SLA):

  • Web Apps SLA: 99,95%
  • Azure SQL Server SLA: 99,99%
  • SLA for Document Storage: 99,99% 

More details: https://azure.microsoft.com/en-us/support/legal/sla/summary/

The availability of our systems is continually monitored and logged. And the current status as well as the uptime history can be accessed at https://status.dotlegal.com.


System and security testing

An authorised external company conducts planned and documented penetration tests once a month, to efficiently identify potential vulnerabilities. If risks classified as "high" or "medium" are found actions to mitigate these will be started as soon as possible. "Low" severity findings will be noted and prioritized among other development tasks.

A.13 Communication security 

Secure communication via SSL 

Communication between the browser and the rest of the system takes place via HTTPS (SHA-2 SSL certificate with a minimum of 2048bit encryption). 

Exchange of data between the customers and the system takes place either via SFTP or built-in functionality for import and export of data, which in turn is protected with HTTPS. 

Confidentiality agreements 

All employees and any subcontractors are subject to confidentiality agreements, which apply both during and after working with the systems. 

A.14 Procurement, development, and maintenance of systems 

Development process

The focal point of our daily work is our joint development process, which is based on modern but well-proven methods such as SCRUM and Kanban. Each product has its product owner with responsibility for planning and prioritising as well as a permanent development team with responsibility for the development and quality assurance. In addition, support speaks directly with the product owner, development team and customers. 

The development process ensures that we have daily back-and-forth discussions that address any challenges and help each other to effective solutions. We have more eyes on the changes we make and actively try to constantly improve our skills and improve the systems we work with. 

All development teams have experienced people onboard to ensure a high level - also when it comes to safety. 

Quality assurance 

Quality assurance elements from the common .legal development process: 

A. Structured process 

i. All work, regardless of character, is visualised as tasks in our task management. All tasks must go through the same overall process with several phases, including code review, internal testing, and acceptance testing. 

B. Automated quality assurance 

i. Version-controlled code  

ii. Continuous integration which continuously builds the code to ensure the integrity 

iii. Automated tests that runs continuously to minimise regression errors 

iv. Automated deployment pipelines which mean that we can safely and with high traceability deploy new code for tests and production environments. 

C. Development, test, and production environment  

i. Dedicated development, testing and production environments to be able to ensure quality on several levels before new code reaches the production environment. 

D. Monitoring and alerting 

i. Our environments are monitored so that we can ensure high uptime and receive alarms about any errors or vulnerabilities as quickly as possible. 

A.15 Supplier conditions 

Supplier agreements  

A. Supplier agreements are established with all customers who use the systems.

B. Any subcontractors must live up to the same security standard and comply with the same security policies as .legal A/S.

Supplier control 

A. .legal performs an annual security check of third party service providers that are part of the overall system.

A.16 Management of information security and personal data breaches 

Procedure for handling information security incidents 

All safety incidents or observed weaknesses are reported to the Executive Board or the safety officer. As soon as a security incident or vulnerability is reported, the following activities are initiated: 

1. The security incident is registered in the company's task management. 

2. In the description of the task, the security incident/weakness is noted in as many details as possible, including as a minimum: 

i. When the incident took place 

ii. What the incident was actually about 

iii. Who reported the incident 

3. The incident is then analysed with a view to the following: 

i. Determine how extensive the incident is 

ii. Which customers are affected 

iii. What needs to be done to either stop the incident or accommodate the incident in the future e.g. for code corrections 

4. Customers identified in point 3 are then informed about the incident and the consequences of the incident, as well as what measures have been taken in the future. 

5. The measures that have been decided are prioritized and implemented.

6. Once the measures have been implemented, the task is closed. 

7. After the problem is solved, the process is described as an incident in the project's incident log. The purpose is to investigate whether there is an underlying problem that may give rise to further improvements or help remedy similar future problems. 

A.18 Compliance

Procedure for compliance with applicable legislation

It is the responsibility of the Executive Board of .legal A/S that regulatory safety requirements are complied with, including: 

A. Act no. 502 of 23 May 2018 on supplementary provisions to the Regulation on the protection of natural persons in connection with the processing of personal data and on the free exchange of such data (Data Protection Act)

B. Personal Data Regulation (Regulation No 2016/679) 

C. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)

Once a year, the .legal A/S Executive Board asks the company's legal function to assess whether changes in legislation require changes to the security policy and/or the system. The assessment is documented and presented to the Executive Board, which reviews and approves it. The result is noted at the board meeting, and any resulting changes are implemented.

 

+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell