Security at Formative Legal

Protecting the work entrusted to us.

An overview of the controls verified for our current pilot infrastructure. Deployment-specific security and data-handling details are available to participating firms on request.

Infrastructure and access

Our current pilot infrastructure is hosted on AWS in London. Administrative access uses AWS single sign-on. The AWS root account has multi-factor authentication, and its long-lived access key has been deactivated.

Storage controls include encryption at rest for the shared file system and backup storage, with public access blocked on the backup buckets. Hosting location alone does not establish the processing location of every connected service; we review the complete arrangement with each firm.

Operational monitoring

AWS management activity is recorded through a multi-region CloudTrail trail with log-file validation and a one-year log retention policy. Infrastructure health alarms and deployment-failure notifications are routed to our operations contact.

Backup and recovery

The current workbench has scheduled database and original-file backups with a 30-day storage lifecycle. On 13 September 2026, we successfully restored a backup database and original files in an isolated environment, then removed the temporary copy. This exercise verified those backup components; it was not a full service recovery exercise.

Data handling and assurance

Model-provider arrangements, retention and deletion requirements depend on the firm's selected deployment and integrations. Contact us for the applicable details. This page is an operational overview and does not represent an independent security certification.

Security enquiries

For a security questionnaire, deployment details or a suspected vulnerability, contact founders@formativelegal.com. Please begin with a description that does not contain client documents, credentials or other sensitive material.

Last reviewed: .