Matter-scoped access
Permissions follow the firm, matter, person, and work they are authorised to see.
LxOS Trust Center
For legal teams in Australia and the United States, LxOS is built to preserve client confidentiality, limit information handling to what is necessary, and keep access, review, and activity accountable.
Last updated 21 July 2026

Our position
Client confidentiality and data minimisation shape how LxOS is designed and operated. We seek to collect and handle only the information reasonably necessary to provide, secure, and support the service. Our security and privacy program is being developed with reference to recognised frameworks as we work toward formal assurance.
Product controls
The strongest safeguards are part of the everyday workflow, not a separate administrative layer.
Permissions follow the firm, matter, person, and work they are authorised to see.
External access is bounded to the relevant matter and can expire or be revoked.
External document views and access changes are designed to leave an accountable history.
AI-assisted document changes remain visible for lawyer review before they become work product.
Operating principles
People should see only the matters and materials required for their role, for only as long as that access is needed.
Information should be collected or generated only when it serves a clear product, security, support, contractual, or legal need.
Client information remains bounded to the authorised firm, matter, and people—not repurposed for advertising or sold to third parties.
Lx assists legal work; it does not replace the professional responsibility to review advice, documents, and decisions.
Sharing, client visibility, and AI-proposed changes should be explicit enough to inspect, understand, and reverse.
Policies matter when they have owners, evidence, review cycles, and a clear account of what is—and is not—verified.
Framework direction
These frameworks guide program development for the markets we currently serve. They are not substitutes for certification, an independent attestation report, or a legal determination of compliance.
For customers in Australia, we are developing our privacy program with reference to the Privacy Act 1988 (Cth) and the APPs, including transparent handling, purposeful collection, controlled use and disclosure, information security, and individual access and correction rights.
The SOC 2 Trust Services Criteria inform how we develop controls for access, change management, system operations, risk management, and confidential information. LxOS has not yet completed an independent SOC 2 examination, and no SOC 2 report has been issued.
ISO/IEC 27001 informs our risk-led approach to security governance, control ownership, access, operations, incident management, and continual improvement. LxOS is not currently certified to ISO/IEC 27001.
For US customers whose work may involve protected health information, HIPAA's administrative and technical safeguards inform our assessment of the required controls and contractual arrangements. LxOS does not currently represent the service as HIPAA compliant.
Questions and diligence
For privacy questions, security reviews, or procurement diligence, contact our team. Information may be provided subject to appropriate confidentiality arrangements.
team@rune-ai.co