Back to MaxLex
Security & Privacy
Start Free
Enterprise-Grade Security for Solo & Small Firms

Your Client Data Is Privileged.
We Engineer It That Way.

MaxLex was built from day one with attorney-client privilege in mind. Every AI interaction is protected by automatic PII sanitization, explicit consent flows, and encryption at every layer.

AES-256 Encryption
PII Auto-Sanitized
ABA Rule 1.6 Compliant
No AI Training on Data
Isolated Per-User Data

Encryption at Every Layer

All data is encrypted both at rest and in transit. We use the same encryption standards trusted by banks, hospitals, and government agencies.

AES-256-GCM Field-Level Encryption

Sensitive fields — SSNs, bank accounts, signatures, client messages, and contact details — are individually encrypted with AES-256-GCM before they ever reach the database. Each value gets a unique initialization vector, so even identical inputs produce different ciphertext. If the database were ever breached, attackers would see only encrypted gibberish.

TLS 1.3 in Transit

Every connection between your browser and MaxLex uses TLS 1.3 — the latest transport layer security protocol — ensuring no data can be intercepted in transit.

Secure JWT Authentication

Session tokens are signed with HMAC-SHA256 and expire automatically, preventing session hijacking and unauthorized access.

Data Flow Architecture

Your BrowserTLS 1.3MaxLex Server
MaxLex ServerPII StrippedAI Engine
Sensitive FieldsAES-256-GCMEncrypted at Field Level

Protected Fields Include:

SSNsBank AccountsRouting NumbersSignaturesClient MessagesContact InfoAdjuster DetailsPayment Tokens

Automatic PII Sanitization

Before any text reaches an AI model — whether through Chat or Voice — MaxLex automatically detects and redacts personally identifiable information. The AI never sees raw client data.

Social Security Numbers

123-45-6789
[SSN_REDACTED]

Phone Numbers

(555) 123-4567
[PHONE_REDACTED]

Email Addresses

[EMAIL_REDACTED]

Credit Card Numbers

4111 1111 1111 1111
[CARD_REDACTED]

Street Addresses

123 Main Street
[ADDRESS_REDACTED]

Dates of Birth

DOB: 01/15/1985
[DOB_REDACTED]

Bar Numbers

Bar #123456
[BAR_NO_REDACTED]

Case Numbers

Case No. 2024-CV-1234
[CASE_NO_REDACTED]

EIN / Tax IDs

EIN: 12-3456789
[EIN_REDACTED]

How PII Shield© Protects Every AI Interaction

Your client data never reaches AI. Here’s exactly what happens behind the scenes.

Step 1

Anonymize

Your document:

John Smith signed the lease at 123 Oak St...

Becomes:

[PERSON_1] signed the lease at [LOCATION_1]...

Names, addresses, SSNs, emails, phone numbers, and account numbers are replaced with safe placeholders.

Step 2

AI Analyzes

Max sees only:

[PERSON_1] signed the lease at [LOCATION_1]. Review for compliance issues...

AI response:

"[PERSON_1]'s lease at [LOCATION_1] contains a non-standard clause..."

The AI model never sees real client data. It works entirely with anonymized content — zero exposure risk.

Step 3

Restore

You see the real result:

"John Smith's lease at 123 Oak St contains a non-standard clause..."

0 PII exposed to AI

Placeholders are swapped back to real names. You get actionable results — the AI got nothing identifiable.

Live Demo

Watch PII Shield© protect client data in real-time

Original Document
Dear Sarah Johnson,

Re: Case #2024-CV-1847

Please contact me at (212) 555-0147 or [email protected] regarding the deposition scheduled for your client (SSN: 287-65-4321) at 450 Park Avenue, New York.

Detected Entities

Name

...

Phone

...

Email

...

SSN

...

Address

...

Compliance & Certifications

MaxLex is designed to meet the security and ethical obligations of legal professionals.

ABA Model Rule 1.6 — Confidentiality

Compliant

MaxLex implements "reasonable efforts" to prevent unauthorized disclosure of client information, as required by Rule 1.6(c). PII is automatically stripped before any data leaves your environment, and all AI interactions are gated behind explicit consent.

HIPAA-Conscious Design

Implemented

While MaxLex is not a covered entity, our architecture follows HIPAA security principles: encryption at rest and in transit, access controls, audit logging, and minimum necessary data exposure for AI processing.

SOC 2 Type II

Roadmap

MaxLex is on the roadmap for SOC 2 Type II certification, covering security, availability, processing integrity, confidentiality, and privacy trust service criteria.

GDPR / CCPA Ready

Implemented

Data retention controls, right-to-deletion capabilities, and transparent data processing disclosures are built into the platform for compliance with privacy regulations.

Isolated Data Architecture

Every MaxLex account operates in complete data isolation. Your cases, documents, contacts, and AI conversations are never accessible to other users — not even other attorneys on the same plan.

Per-User Data Isolation

Every database query is scoped to your user ID. There is no shared data pool between accounts.

Role-Based Access Control

Admin and user roles with procedure-level enforcement. Protected endpoints verify identity before every operation.

Automatic Session Timeout

Sessions expire automatically to prevent unauthorized access from unattended devices.

Third-Party Services

MaxLex uses the following third-party services. Here's exactly what data each receives:

Google Gemini API

Data sent: Sanitized prompts only (PII stripped)

Purpose: AI reasoning for Chat & Voice

Manus Forge LLM

Data sent: Sanitized prompts only (PII stripped)

Purpose: Fallback AI processing

Stripe

Data sent: Email, name, payment info

Purpose: Subscription billing

S3 Storage

Data sent: Encrypted file bytes

Purpose: Document storage

Ready to Practice with Confidence?

Join attorneys who trust MaxLex to protect their clients' data while supercharging their practice.