Our Information Security Policy

 In Compliance, FCPA, FISA

The foundation of the LegalKaizen privacy framework rests upon a robust and comprehensive security strategy. Our policies, detailed within the LegalMaps / LegalKaizen Security Policy, are meticulously crafted and ISO/IEC 27001 Compliant. This dedication ensures the preservation of three critical pillars for your data:

 

  • Confidentiality, restricting access only to those authorised;
  • Integrity, safeguarding the accuracy and completeness of information; and
  • Availability, ensuring authorised users can access information when required. 

 

The purpose of this policy is explicitly designed to protect and preserve the security, confidentiality, integrity, and availability of information owned by or in the care of LegalMaps / LegalKaizen and its customers, safeguarding technology assets and client information from unauthorized use, disclosure, modification, or damage.

 

Protecting the interests of our clients is paramount, and our governance structure is built around this requirement. The Security Policy document is designed to protect against unauthorized access to or use of information that could result in substantial harm or inconvenience to LegalMaps / LegalKaizen, our customers, or the individuals to whom the information relates. 

 

We exercise due care when interacting with customers and consumers to protect privacy, ensuring that sensitive information is only revealed after taking reasonable steps to verify the identity of the receiving party and their authority to receive such information. Furthermore, our comprehensive compliance measures actively identify and incorporate external security standards, including adherence to requirements related to Data Protection and Privacy of Personal Information, and relevant standards like the Gramm Leach Bliley Act (GLBA) and the Personal Information and Electronic Documents Act (PIPEDA).

 

To confirm that our protective measures remain up to date, LegalKaizen maintains a formalized and disciplined review cycle. The policy mandates review at least annually to determine its effectiveness. This review process explicitly monitors for the effects of changes to technology and, critically, changing laws and regulations particular to the country in which the Information Systems reside. Through the ongoing efforts of our Security Compliance team, LegalKaizen translates these requirements to construct the proper balance and technical controls necessary to drive continuous compliance. This continuous assessment, combined with our rigorous risk assessment methodologies, guarantees our policy evolves proactively to meet new threats and regulatory demands, ensuring unwavering protection of client interests.

Our privacy and security policy can be accessed at this link.