CortexLex
Home

Security

Your information deserves care, control and clarity.

CortexLex protects firm and client information through controlled access, private documents and firm separation.
  • No card
  • No automatic charges
  • Cancel anytime
Layered composition representing isolation and controlled access

What worries you

Four questions every firm should ask.

We do not talk about security in the abstract. These are the situations that actually come up in a practice, and what CortexLex does about each one.

What if someone signs in with my partner’s password?

Everyone has their own account.

Nobody shares credentials. Two-step verification adds a second barrier, and open sessions can be closed from any device.

  • Two-step verification with recovery codes
  • Active sessions visible and revocable one by one
  • Changing the password closes every other session at once

Can another firm see my files?

Each firm’s information lives apart.

Isolation does not depend on the program remembering to filter: the database itself refuses any query that tries to cross from one firm to another.

  • Separation enforced in the database, not only in the application
  • The active organisation is checked before any read or write
  • Someone working across firms never mixes their information

Will my assistant see the fees?

You decide who sees and does what.

Permissions follow responsibility, not hierarchy. A matter marked confidential does not appear for someone who should not see it, not even in search.

  • Separate permissions to read, create, share and administer
  • Confidential matters hidden even from global search
  • The client portal never shows internal notes

How is shared content controlled?

Each action checks the current permission.

The application checks authorization again when content is opened, downloaded, or shared. Generated documents retain the model and values used so they can be reviewed.

  • Downloads re-check authorization
  • Every generated document keeps its origin and its data
  • Reviews and confirmations appear within the authorized matter

Real control

Access is managed from the application.

The firm administrator changes permissions and can withdraw access that no longer applies. Detailed administrative access and download logging will be available before it is offered as complete auditing.

  • Change a member’s access on the spot
  • Withdraw a client’s portal access
  • Review each matter’s authorized context
A

Team and permissions

Who can see and do what

A
Ana RodríguezLead lawyer
Full access
L
Luis CamachoLawyer
Own matters
S
Sofía RuizAssistant
No financials

Account protection

Two-step verificationConfigured
Available
Access recoveryAvailable
Available

Portal controls

Invitation-only accessThe firm chooses who enters
Firm permissionsInformation stays separated
Shared contentThe firm chooses what to publish
9:41
CCortexLexAR

Team and permissions

Ana RodríguezLead lawyer · Full access
Luis CamachoLawyer · Own matters
Sofía RuizAssistant · No financials

How it is built

The practices behind all of the above.

Technical decisions explained without jargon, because they are part of what you are buying.

Documents are never public

Files have no permanent address that can be shared by accident. Every download re-checks authorization at that moment.

Uploads have format validation

Every incoming file is validated by type, size and actual content, not just its extension. Quarantined anti-malware analysis is not offered until that control is deployed and verified.

Protected in transit and at rest

Information travels encrypted between the device and CortexLex, and stays encrypted while stored.

Backup and recovery

Backups and restore procedures are maintained to respond to a service interruption.

Incident response

Security events are investigated according to their impact and communicated in line with contractual commitments and applicable law.

Want to see it applied to your firm?

Request a demo