Security
Your firm's work, kept where it belongs
This page answers what careful firms ask before they let any assistant near client work: where the information lives, who can see it, what we will never do with it, and where we stand on the standards your reviewers will ask about. Our Trust Centre carries the live detail.
Independent standards
Being audited against the standards careful firms ask for
A SOC 2 report and an ISO certificate are issued at the end of an audit period, not the start of one. Alesis is in that period now, and its UK GDPR compliance is already in place. The Trust Centre shows where each one stands.
SOC 2 Type 2
The audit period is under way. An independent auditor examines how we protect the information firms give us over a period of months, not on a single day, and the report issued at the end of it is the one your IT reviewers will ask to see.
ISO 27001
Certification is under way against the international standard for managing information security: knowing what you hold, who can reach it, what could go wrong and what you would do about it, examined by an outside certification body.
ISO 42001
Certification is under way against the standard written for organisations that build and run AI. It asks how a system is designed, watched, governed and corrected: the questions a COLP asks before trusting an assistant with client work.
UK GDPR
Alesis is compliant with UK GDPR and the Data Protection Act 2018. The records, agreements and procedures behind that are in place, reviewed, and ready for a firm's due diligence.
Your information stays in the UK and the EU
Not a region you pick from a list. It is how Alesis is built, for every firm, on every matter.
- Held in the UK, processed in the UK and the EU
- Your firm's information is stored in the UK. When Alesis works on it, that happens in the UK and the EU, and never anywhere else.
- Kept apart from every other firm
- Your firm's work is kept apart from every other firm's. Nothing your firm uploads, asks or drafts can surface for anyone else, and nothing of theirs can surface for you.
- Never used for training
- Nothing you upload, ask or draft is used to train anything for anyone else. Your work helps Alesis answer you; it does not teach a model that answers anybody else.
- A UK company behind it
- Alesis is built and run by L25 Limited, registered in England and Wales. When you write to us, the people who answer are the people responsible for the product, and they are here in the UK.
Security fit for client work
Each of these exists because someone in the firm has to answer for the work, and for what was done with the client's papers along the way.
- Matters have their own walls
- Inside the firm, people see only the matters they are on. Seniority does not grant a view: even a firm owner sees a matter only once they are added to it.
- Sign-in worth the name
- Every account proves its email address before it can work, only a firm's own addresses are accepted, and every account can add two-factor authentication and passkeys.
- Documents are evidence, never instructions
- Alesis treats every document you upload as material to be read and weighed, not as orders to be followed. The other side's paperwork is something it examines, not something it obeys.
- Nothing leaves on its own
- Alesis cannot file, serve or email anything. It prepares the work; your people decide what goes out, and when.
- Answers keep their receipts
- Every answer keeps the sources it rested on and the steps it took to get there, so you can show afterwards what was relied on and where it came from.
Your data. Your decisions.
You stay in control of your firm's information
Access, matter by matter
You decide who is on each matter, hand conduct over when it moves, and take someone off it the moment they leave the file. Nobody is on a matter by default.
Sign-in you set the bar for
Two-factor authentication and passkeys are there for every account, and you choose who holds the keys to the firm: owners, admins and members are set by you, not by us.
Sources your firm vouches for
Alesis reads official bodies and regulators as a matter of course. Your firm decides which other publishers it trusts, and who inside the firm may approve one; anything the firm adds is always named as the firm's own choice.
Remove it when you choose
Delete a conversation, a document, a person's access or the whole firm whenever you decide. Nothing is buried behind a support ticket, and leaving is never made hard.
Put your due diligence to us in writing
Whatever your COLP, your insurers or your IT reviewers need to ask, send it over. Every answer comes back in writing, signed by the people responsible for it, so your file shows exactly what was promised. The policies and the live status of each standard are on the Trust Centre, open to anyone.