Conlegie

Security

Last updated August 1, 2026

Contract content is sensitive by nature, and our approach to security is built around that. Here's a plain-language summary of how we think about it — if you're evaluating Conlegie for procurement or a security review, contact us and we'll walk through it in more detail, including answering a security questionnaire directly.

Encryption

Contract data is encrypted in transit using TLS and at rest on the infrastructure that stores it. Access to production data is limited to the small number of team members whose role requires it.

Hosting

We host on infrastructure provided by established cloud providers with EU data-residency options, and default new customer accounts to EU-region storage unless a different region is specifically required.

Data use

Contract content you process through Conlegie is used to generate your review and is not used to train models shared across other customers. Playbook configurations, redlines, and obligation data belong to your organization and are never used for any purpose beyond delivering the service back to you.

Data retention & deletion

You control how long contract data is retained within your account. On request, or on contract termination, we delete customer data within the timeframe specified in your subscription agreement, subject to any legal retention obligations.

Access controls

Customer accounts support role-based access control, so review permissions, playbook editing, and administrative functions can be scoped to the right people on your team. Enterprise plans add SSO and SCIM provisioning.

Our compliance roadmap

As an early-stage company, we're building our formal compliance program deliberately rather than claiming certifications before they're earned. We are actively working toward SOC 2 Type II and are happy to share our current control documentation and roadmap with prospective customers under NDA.

Reporting a vulnerability

If you believe you've found a security issue with our website or product, please report it to security@conlegie.com. We take reports seriously and will respond promptly — please give us reasonable time to investigate and address any issue before public disclosure.