Security and data handling

Security language should be as precise as the analysis.

LexWorks communicates the controls it has, the data it uses, and the boundaries attorneys should understand—without making unsupported certifications.

Upload and retention

Secure parsing with an explicit retained record.

Punch files are securely uploaded for parsing. Original uploaded files are deleted after parsing. LexWorks retains workspace-scoped normalized source evidence, reconstructed shifts, findings, review decisions, assumptions, snapshot metadata, report metadata, and audit events so authorized users can resume and reproduce the review.

Uploads are parsed through a secure server endpoint. File deletion does not mean the normalized analysis record is deleted.

Authenticated sessionsServer-issued, HTTP-only session cookies with SameSite protection; production adds the Secure flag.
Workspace isolationUsers, matters, and retained review records are scoped to authenticated workspaces with server-side enforcement.
Role separationWorkspace roles and separate platform-administration roles limit access to the work each person needs.
CSRF protectionState-changing routes require anti-forgery protection, including authentication, matter, review, and export actions.
Metadata-only loggingAudit events capture activity metadata. Raw punch rows and full uploaded file contents must not be logged.
Reviewable activityRegistration, login, upload, decisions, report generation, snapshots, and denied access can be audited.

Product scope

Punch records are one part of legal review.

The application does not incorporate payroll, HR, scheduling, waiver, policy, testimony, or other external records unless reviewed separately outside the punch-data analysis. It surfaces potential findings; it does not determine liability, compensation, or final damages.

Give your next matter a clearer first read.

Create a workspace and explore the complete workflow with a 14-day trial. No card required.

Start free trial