Security
How Legau handles security
Legau
Security is a top priority

Datacenter
Hosted with Microsoft Azure
- Azure East US or EU
- Layer 4-7 DDoS protection built in
- Fire detection and extinction
- Monitoring and surveillance

Firewall
Cloudflare
- DDoS attack protection
- Protection against SQL Injection
- Protection against Cross-site scripting
- Protection against HTTP Protocol Violations
- Protection against Server Side request forgery
- Bot Detection

In-transit encryption
Encryption
- Mandatory web access encryption (HTTPS)
- Mandatory strong encryption protocols: TLS v1.2+
- Mandatory strong cipher suites
- Forward secrecy enabled

Assets
Customer Assets
- Customer assets are defined as any documents that are uploaded in our system by the customer or by Legau on behalf of the customer
- Assets are stored on Azure
- Data is encrypted on transit (min TLS v1.2) and on-rest
- External access is restricted to our compute infrastructure
- Access keys are rotated frequently
- Each customer has their own container

Security
Security by Design
- Injection and cross-site prevention
- Need-to-know basis
- SSO support
- Security language in user stories
- Zero-trust firewall
