FastLegal is SOC 2 Type II and ISO 27001:2022 certified. Reports are available under NDA.
All customer data is encrypted in transit (TLS 1.3) and at rest (AES-256 with key rotation every 90 days).
All customer data hosted in AWS Mumbai (ap-south-1) by default. EU and US data residency available on Enterprise plans.
Access to production is restricted to a small number of personnel using hardware MFA, with all activity logged and reviewed monthly.
We run continuous vulnerability scans and bi-annual penetration tests with reputable third-party firms.