View Categories

Account Security & Privacy

Legal Ready has implemented a range of security measures to protect the eBrief Ready platform and the data of its clients. This article explains those measures and how they benefit you as a subscriber.

ISO 27001 certification

Legal Ready is independently certified to ISO 27001:2022 — the leading global industry standard for information security management. This certification provides a framework for the way organisations manage the security of their data assets.

ISO 27001 is not a compulsory regulatory requirement. By undergoing independently verified certification, Legal Ready ensures the best possible protection for the eBrief Ready platform and its subscribers.

Key security measures

Two-factor authentication (2FA) — Legal Ready enforces mandatory two-factor authentication for all eBrief Ready accounts. In addition to your username and password, 2FA requires an additional verification step via SMS code or authenticator app. Even if someone obtains your password, they cannot access your account without this second step.

Data storage — All client documents are held securely on Amazon AWS servers located in Sydney for Australian users and London for UK users. Your data stays within your jurisdiction.

Encryption — All data from third-party services such as Amazon Web Services, Elastic Cloud and Elastic Email is encrypted in transit and, where possible, encrypted at rest. User account passwords are encrypted and the unencrypted password is not accessible to any member of the Legal Ready team.

Vulnerability management — The software libraries used by the eBrief Ready platform are routinely checked for vulnerabilities as part of the development and deployment process. A deployment cannot proceed until any identified vulnerabilities have been rectified.

Confidentiality agreements — All Legal Ready team members sign confidentiality agreements. Their access to client data is limited to what is required for development or troubleshooting purposes only.

Automated monitoring and backup Legal Ready has automated systems in place for error detection and reporting, and a robust system for the automated backup of critical user-provided data.

Access control

Legal Ready applies the following access control principles across its platform:

  • Principle of least privilege — accounts are granted the minimum access necessary to perform their role
  • Segregation of duties — responsibilities are separated to reduce the risk of human error or misuse
  • Approval and provisioning — access to applications, databases and documents is approved by designated roles, with the approving role separate from the provisioning role
  • Regular review — user access rights are regularly reviewed and deprovisioned as necessary

AI data confidentiality

Using AI to read confidential documents on eBrief Ready does not compromise their confidentiality. As set out in our Responsible Use of AI Policy, all AI features operate within strict technical and contractual safeguards designed to preserve privacy and legal privilege.

Documents uploaded to the platform remain securely hosted on AWS servers in Australia. Some AI-related tasks may be processed on Google servers outside Australia. Where this occurs, robust safeguards apply including encryption in transit and at rest, strict access controls, and region-aware data processing preferences. Further information on Google Cloud’s security standards is available here.

We do not use customer data to train generative AI models, and we do not permit third parties to use our customers’ data for that purpose.

For further information or assistance, please do not hesitate to reach out to our dedicated Support Team via support@legalready.ai or +61 3 9020 4456.