Security
Last updated: July 2026
1. Encryption
All data in transit is encrypted with HTTPS/TLS. Documents you upload are stored in a private storage bucket that only your account — and anyone you explicitly grant access to — can reach.
2. Data isolation
Every table in our database enforces row-level security, so your assets, liabilities, and documents are scoped to your account at the database layer, not just in application code. No user can query another user's data.
3. Account protection
- Two-factor authentication — add an authenticator app as a second sign-in factor from Settings.
- Login history — review recent sign-ins to your account at any time.
- Device management — see and revoke devices that have accessed your account.
- Account access notifications — get notified of sign-ins from a new device or location.
4. Audit trail
Sensitive actions on your account are recorded in a tamper-evident, hash-chained audit log — each entry cryptographically links to the one before it, so the log itself can be verified for integrity, not just read.
5. Household & emergency access
Sharing is opt-in and scoped. Household members see only what you choose to share, and emergency access links can be time-limited, revoked, or gated behind a break-glass request you control.
6. Responsible disclosure
If you believe you've found a security issue in Legiqo, please report it to security@legiqo.co. We ask that you give us a reasonable window to investigate and fix an issue before disclosing it publicly.
7. More information
See our Privacy Policy for what we collect and how it's used.