Security for confidential legal work
AI for confidential legal work—built around Canadian privacy and firm control.
Your firm's work stays yours.
Use Canadian legal AI on private matter documents with Canadian application hosting, no AI training on client data, best-effort PII minimization, encrypted processing, controlled provider retention, and no TruLexa server-side conversation archive.
No credit card required
Firm control by design
- Canadian data residency
- No AI training on client data or conversations
- AES-256 at rest · TLS 1.3 in transit
- No server-side conversation archive
The controls law firms ask about first
Clear answers on where client information goes, how it is used, and how long it remains available.
Canadian data residency
TruLexa application hosting and core AI workflow processing run in Canadian data centres. Prompts, documents, uploads, and generated work remain in Canada, including when approved external AI providers process a selected task on Canadian servers.
Your data never trains AI models
Client information, prompts, chats, documents, and generated work are not used to train AI models or build advertising profiles.
No server-side conversation archive
Completed conversations are not archived on TruLexa servers. Session history stays on the user's device under the firm's endpoint controls.
Personal information is minimized
Direct identifiers are masked on a best-effort basis before AI processing and restored in the returned work product. This safeguard supports—but does not replace—professional review.
Confidential matter work
Legal AI requires more than generic cloud security.
Legal work can include privileged communications, litigation strategy, evidence, contracts, financial information, and sensitive client records. TruLexa limits collection, minimizes direct identifiers, restricts administrative access, and deletes transient provider copies when processing ends.
The responsible lawyer or notary remains in control of the matter and final work product.
Data flow
Your matter. Your data. Controlled at every step.
Five defined stages from your device to the completed legal work product.
Upload
Your document travels from a signed-in session over an encrypted connection.
Minimize
Direct identifiers are masked on a best-effort basis before AI processing and restored in the returned work product.
Process
Only approved services required for the selected legal task receive the request on Canadian servers under TruLexa's data-handling controls.
Return
The completed work streams back to the user's device over an encrypted channel.
Delete
Provider copies are deleted when processing ends, and TruLexa keeps no server-side conversation archive.
Firm controls
Security, privacy, and compliance at a glance
The controls your managing partner, privacy officer, and IT team need to evaluate TruLexa.
Security
- AES-256 encryption at rest and TLS 1.3 in transit
- Role-based access control and separation of duties
- Multi-factor authentication for administrative systems
Privacy
- Canadian application and AI workflow processing
- No model training, advertising use, or user profiling
- Metadata-only operational logging and automatic PII minimization
Compliance
- Controls aligned with PIPEDA and Alberta and BC PIPA
- PHIPA-aligned controls for applicable Ontario health information
- SOC 2 Type II readiness work in progress
Vendor due diligence
Security answers for every firm decision-maker
Evaluate TruLexa's data handling, access controls, privacy alignment, and assurance roadmap before confidential matter work is introduced.
- Managing partner
Where is our legal work handled?
Application hosting and core AI workflow processing run in Canadian data centres.
- Privacy officer
Does client data train AI?
No. Client prompts, conversations, documents, and generated work are not used to train AI models.
- Information technology
How is information protected?
AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, separation of duties, and MFA for administrative systems.
- Risk and procurement
What can our firm review?
Request the security package, privacy documentation, and support for your vendor questionnaire.
Security questions
What Canadian legal teams ask before using AI
Does TruLexa use client data to train AI models?
No. Client information, prompts, conversations, documents, and generated work are not used to train AI models or build advertising profiles.
Where does TruLexa process Canadian legal work?
TruLexa application hosting and core AI workflow processing run in Canadian data centres. Approved external AI providers process applicable requests on Canadian servers under TruLexa's technical, contractual, transient-retention, and no-training controls.
Who is the Privacy Officer and how can firms review privacy and data-processing terms?
Fred Zhang is AIstrova's designated Privacy Officer for TruLexa. Firms may request TruLexa's privacy and data-processing terms, current service-provider/subprocessor schedule, and related security or privacy documentation at privacy@aistrova.com.
Does TruLexa anonymize all personal information?
TruLexa masks direct identifiers before AI processing on a best-effort basis. Detection can vary with context, formatting, language, and scan quality, so legal professionals must still review the material.
Is TruLexa SOC 2 Type II certified?
No. SOC 2 Type II readiness work is in progress. TruLexa does not represent that this work is complete or that certification has been obtained.
How does TruLexa support Canadian privacy requirements?
TruLexa maintains controls aligned with PIPEDA, Alberta PIPA, BC PIPA, and—where applicable—Ontario PHIPA. Firms should evaluate those controls against their own obligations and matter requirements.
Firm due diligence
Put TruLexa through your security review.
Request the TruLexa Security Package, privacy documentation, and vendor-questionnaire support—or start a full 15-day trial now.