MVSP Self-Assessment
Minimum Viable Secure Product (MVSP) control status for Centralize Legal. Assessment date: July 4, 2026. Reviewed at least annually.
Reference: mvsp.dev. This page supports Clio Securiti questionnaire completion and customer security reviews.
Print to PDF: use your browser's Print → Save as PDF on this page for a one-page summary (landscape recommended).
| Control | Title | Status | Notes |
|---|---|---|---|
| 1.1 | External vulnerability reports | Yes | security.txt at /.well-known/security.txt; disclosure policy on /security#vulnerability-disclosure; security@centralizelegal.com |
| 1.2 | Customer testing | Planned | Coordinated testing on request for enterprise customers; production-like staging TBD |
| 1.3 | Self-assessment | Yes | This page; updated at least annually |
| 1.4 | External penetration testing | Planned | Lightweight pen test before paid customers; full annual third-party test planned |
| 1.5 | Security training | Planned | Founder-led secure development practices; formal role-based training as team grows |
| 1.6 | Compliance standards | No | No SOC 2 / ISO 27001 yet; MVSP-aligned architecture; GDPR-aware DPA available |
| 1.7 | Incident handling | Yes | 72-hour breach notification in DPA; internal incident runbook |
| 1.8 | Data handling / media sanitization | Planned | Cloud provider-managed storage; documented delete-on-disconnect and offboard purge |
| 2.1 | Single sign-on | Yes | WorkOS AuthKit SSO for all customers at no extra cost |
| 2.2 | HTTPS-only | Yes | TLS on Railway; HSTS header; auth cookies Secure via WorkOS |
| 2.3 | Security headers | Yes | HSTS, X-Frame-Options, CSP on public pages, no-store on sensitive API routes |
| 2.4 | Password policy | Yes | N/A for local passwords — authentication delegated to WorkOS / customer IdP |
| 2.5 | Security libraries | Yes | TypeScript, parameterized SQL, validated index schema, ORM-free but typed repositories |
| 2.6 | Dependency patching | Yes | GitHub Dependabot enabled; npm audit in CI |
| 2.7 | Logging | Yes | Metadata-only audit_log; auth events; no privileged payloads in logs |
| 2.8 | Encryption | Yes | TLS in transit; envelope encryption + GCP KMS at rest for OAuth tokens |
| 3.1 | List of sensitive data | Yes | Documented in Privacy Policy, Security Overview, master plan §3.3 |
| 3.2 | Data flow diagram | Yes | Security Overview + data-residency statement describe flows |
| 3.3 | Vulnerability prevention | Yes | Tenant-scoped queries, MCP auth gate, input validation on index rows, automated tests |
| 3.4 | Time to fix vulnerabilities | Planned | 90-day patch target documented; critical/active-exploit prioritized |
| 3.5 | Build and release process | Yes | GitHub version control; CI on push; secrets in Railway env / KMS only |
| 4.1 | Physical access | Yes | Inherited from cloud providers (Railway, Google Cloud) — no owned datacenters |
| 4.2 | Logical access | Yes | Per-user OAuth delegation; tenant isolation; MFA via customer IdP / WorkOS |
| 4.3 | Sub-processors | Yes | Public list at /subprocessors; annual review |
| 4.4 | Backup and disaster recovery | Planned | Railway Postgres backups; formal DR test plan scheduled |
BYO-AI boundary
Content retrieved via the service is transmitted to the AI environment the Customer connects. That AI provider is a Customer-connected system under the Customer's own agreement, not a Subprocessor of Centralize Legal.
Contact
Security: security@centralizelegal.com · Support: support@centralizelegal.com
Related: Security Overview · DPA · Subprocessors