MVSP Self-Assessment

Minimum Viable Secure Product (MVSP) control status for Centralize Legal. Assessment date: July 4, 2026. Reviewed at least annually.

Reference: mvsp.dev. This page supports Clio Securiti questionnaire completion and customer security reviews.

Print to PDF: use your browser's Print → Save as PDF on this page for a one-page summary (landscape recommended).

Control Title Status Notes
1.1 External vulnerability reports Yes security.txt at /.well-known/security.txt; disclosure policy on /security#vulnerability-disclosure; security@centralizelegal.com
1.2 Customer testing Planned Coordinated testing on request for enterprise customers; production-like staging TBD
1.3 Self-assessment Yes This page; updated at least annually
1.4 External penetration testing Planned Lightweight pen test before paid customers; full annual third-party test planned
1.5 Security training Planned Founder-led secure development practices; formal role-based training as team grows
1.6 Compliance standards No No SOC 2 / ISO 27001 yet; MVSP-aligned architecture; GDPR-aware DPA available
1.7 Incident handling Yes 72-hour breach notification in DPA; internal incident runbook
1.8 Data handling / media sanitization Planned Cloud provider-managed storage; documented delete-on-disconnect and offboard purge
2.1 Single sign-on Yes WorkOS AuthKit SSO for all customers at no extra cost
2.2 HTTPS-only Yes TLS on Railway; HSTS header; auth cookies Secure via WorkOS
2.3 Security headers Yes HSTS, X-Frame-Options, CSP on public pages, no-store on sensitive API routes
2.4 Password policy Yes N/A for local passwords — authentication delegated to WorkOS / customer IdP
2.5 Security libraries Yes TypeScript, parameterized SQL, validated index schema, ORM-free but typed repositories
2.6 Dependency patching Yes GitHub Dependabot enabled; npm audit in CI
2.7 Logging Yes Metadata-only audit_log; auth events; no privileged payloads in logs
2.8 Encryption Yes TLS in transit; envelope encryption + GCP KMS at rest for OAuth tokens
3.1 List of sensitive data Yes Documented in Privacy Policy, Security Overview, master plan §3.3
3.2 Data flow diagram Yes Security Overview + data-residency statement describe flows
3.3 Vulnerability prevention Yes Tenant-scoped queries, MCP auth gate, input validation on index rows, automated tests
3.4 Time to fix vulnerabilities Planned 90-day patch target documented; critical/active-exploit prioritized
3.5 Build and release process Yes GitHub version control; CI on push; secrets in Railway env / KMS only
4.1 Physical access Yes Inherited from cloud providers (Railway, Google Cloud) — no owned datacenters
4.2 Logical access Yes Per-user OAuth delegation; tenant isolation; MFA via customer IdP / WorkOS
4.3 Sub-processors Yes Public list at /subprocessors; annual review
4.4 Backup and disaster recovery Planned Railway Postgres backups; formal DR test plan scheduled

BYO-AI boundary

Content retrieved via the service is transmitted to the AI environment the Customer connects. That AI provider is a Customer-connected system under the Customer's own agreement, not a Subprocessor of Centralize Legal.

Contact

Security: security@centralizelegal.com · Support: support@centralizelegal.com

Related: Security Overview · DPA · Subprocessors