Information Security Addendum
This Information Security Addendum forms part of the Agreement between OrdoLux and the Customer and supplements the Data Protection Addendum. It describes the technical and organisational measures referenced at paragraphs 2.5 and 4.1 of the Data Protection Addendum.
Contents
- Scope and purpose
- Infrastructure overview
- Technical security measures
- Organisational security measures
- Personnel security
- Physical and environmental security
- Vulnerability and penetration testing
- Incident management and breach response
- Data retention and deletion
- Independent certifications and assurance
- Sub-processors
- Data residency and international transfers
- Backups and disaster recovery
- Review and updates
1. Scope and purpose
This Addendum describes the technical and organisational measures implemented by OrdoLux (the Supplier) to safeguard Protected Data processed in the provision of the Services, as referenced at paragraphs 2.5 and 4.1 of the Data Protection Addendum.
OrdoLux is built and hosted on the Base44 platform (a Wix-owned company). The security measures described in this Addendum are implemented through a combination of OrdoLux's own application-level controls and the platform-level security infrastructure provided by Base44. Where measures are provided by Base44, this is stated explicitly.
2. Infrastructure overview
OrdoLux is a cloud-based legal practice management platform built on the Base44 platform (a Wix-owned company). Application data is hosted on Google Cloud infrastructure provided by Base44. Customer documents (PDFs, Word files, Excel files, and other matter documents) are stored within the Customer's own Microsoft 365 / SharePoint tenancy and are not hosted on OrdoLux infrastructure. OrdoLux accesses these documents via the Microsoft Graph API using scoped OAuth permissions limited to designated SharePoint sites.
OrdoLux application data (matter records, time entries, billing data, tasks, client and contact information, audit logs) is stored on Base44 infrastructure. Data residency and international transfer safeguards are addressed in paragraph 7 of the Data Protection Addendum and in section 12 of this Addendum.
3. Technical security measures
3.1 Encryption
- Data in transit: All data transmitted between users, OrdoLux, and Base44 infrastructure is encrypted in transit using TLS (Transport Layer Security).
- Data at rest: OrdoLux application data stored on Base44 infrastructure is encrypted at rest. Base44's platform-level encryption covers all stored application data, including database records, files, and backups.
- Document storage: Customer documents remain on the Customer's own Microsoft 365 / SharePoint tenancy, which benefits from Microsoft's own encryption in transit and at rest.
- Secrets management: API keys, credentials, and other secrets used by OrdoLux are stored in Base44's encrypted secrets vault. Secrets are only accessible from the application backend and are never exposed to end users.
3.2 Authentication and access control
- Authentication: Access to the OrdoLux application is managed through authenticated user accounts. OrdoLux supports Microsoft (Microsoft 365) single sign-on (SSO) via OAuth 2.0, ensuring users authenticate through their own organisation's identity provider.
- Role-based access: OrdoLux enforces role-based access controls within the application, restricting user access to data and functionality according to their assigned role (e.g. fee earner, administrator, bookkeeper).
- Tenant isolation: OrdoLux operates a multi-tenant architecture with row-level security (RLS) that isolates each firm's data. Users in one firm cannot access data belonging to another firm. All entity queries are scoped by tenant identifier, and row-level security is enforced at the database level.
- Microsoft Graph scope limitation: OrdoLux's access to the Customer's Microsoft 365 environment is limited to scoped OAuth permissions for reading and writing files within designated SharePoint sites, sending emails, and accessing calendar data. OrdoLux does not have tenant-wide administrative access and cannot access anything outside the scopes the Customer explicitly authorises.
- Rate limiting: All public endpoints are rate-limited by default at the platform level to protect against abuse and automated attacks.
3.3 Application security
- OrdoLux application data is stored and managed through Base44's managed backend, which handles data access, permissions, and security controls.
- All API access to OrdoLux backend functions is authenticated and authorised.
- OrdoLux maintains audit logs of key activities within the application, including matter changes, time recording, billing actions, and document access.
- Security scanning is performed on the application, including checks for overly permissive data access rules, exposed credentials, and authentication gaps, before each deployment.
4. Organisational security measures
4.1 Security management system
Base44 maintains an ISO 27001 certified Information Security Management System (ISMS) that governs security practices across people, processes, and technology. The ISMS is subject to regular internal audits and independent external assessment as part of the SOC 2 Type II audit cycle. OrdoLux benefits from this ISMS as a hosted application on the Base44 platform.
4.2 Security monitoring
- Base44 provides ongoing security monitoring of the infrastructure on which OrdoLux is hosted.
- Base44 maintains industry-standard security practices for vulnerability management, patching, and infrastructure hardening.
- Rate limiting and access controls are monitored at the platform level.
5. Personnel security
Access to OrdoLux infrastructure and Base44 backend systems is restricted to authorised personnel with a legitimate business need. The following personnel security measures are implemented as part of Base44's ISO 27001 certified ISMS:
- Confidentiality: All personnel with access to systems handling Protected Data are subject to confidentiality obligations.
- Access management: Access to production systems is granted on a least-privilege basis and reviewed regularly. Access is revoked promptly when personnel leave or change roles.
- Security awareness: Personnel receive security awareness training as part of the ISMS requirements under ISO 27001 Annex A.7 (Human Resource Security).
- Background verification: Background checks are conducted on personnel prior to granting access to production systems, in accordance with ISO 27001 Annex A.7.1.
6. Physical and environmental security
OrdoLux application data is hosted on Google Cloud infrastructure provided by Base44. Physical and environmental security controls for the underlying data centres are managed by the cloud infrastructure provider and include:
- Physical access controls (biometric scanners, security personnel, visitor logging) at data centre facilities.
- Environmental controls including fire suppression, climate control, and power redundancy with backup generators.
- These controls are assessed as part of Base44's SOC 2 Type II audit and ISO 27001 certification (Annex A.11, Physical and Environmental Security).
Customer documents stored in the Customer's own Microsoft 365 / SharePoint tenancy benefit from Microsoft's own physical and environmental security controls, which are independently certified under ISO 27001, SOC 2, and other frameworks.
7. Vulnerability and penetration testing
- Penetration testing: Base44 conducts regular penetration testing of the platform using both internal and third-party security teams. Testing covers infrastructure, application layers, and authentication mechanisms.
- Bug bounty program: Base44 operates a bug bounty program for responsible vulnerability disclosure, enabling external security researchers to report potential security issues.
- Security scanning: OrdoLux applications are scanned for security issues before each deployment, including package vulnerability scanning (checking third-party libraries for known CVEs), code vulnerability scanning (analysing code for exploitable patterns), and exposed credentials detection.
- Patch management: Base44 maintains a vulnerability management programme with timely patching of infrastructure components and dependencies. Critical vulnerabilities are prioritised based on severity assessment.
8. Incident management and breach response
8.1 Incident response plan
Base44 maintains an incident response plan as part of its SOC 2 Type II and ISO 27001 certified controls. The plan covers detection, containment, eradication, recovery, and post-incident review. OrdoLux relies on Base44's incident response capabilities for infrastructure-level incidents and maintains its own application-level monitoring for OrdoLux-specific issues.
8.2 Breach notification
- In the event of a personal data breach affecting Protected Data, OrdoLux will notify the Customer without undue delay and in any case within 72 hours of becoming aware of the breach, in accordance with the Data Protection Addendum and applicable Data Protection Laws.
- OrdoLux will provide the Customer with sufficient information to allow the Customer to meet its own breach notification obligations under the GDPR / UK GDPR, including the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
- Following resolution of an incident, a post-incident review is conducted to identify root cause and implement preventive measures.
9. Data retention and deletion
- During the Agreement: Protected Data is retained for the duration of the Agreement in accordance with the Customer's instructions. The Customer controls what data is entered, stored, and deleted within the Services at all times.
- Upon termination: Upon termination or expiry of the Agreement, OrdoLux will delete or return all Protected Data in accordance with paragraph 10 of the Data Protection Addendum, within a period not exceeding 90 days from the date of termination, unless Applicable Law requires longer retention.
- Customer-controlled backups: Because OrdoLux backs up application data nightly to the Customer's own SharePoint site as CSV files, the Customer retains continuous access to its data and can verify deletion independently.
- Document data: Customer documents stored in the Customer's own Microsoft 365 / SharePoint tenancy are not retained by OrdoLux upon termination, as they never leave the Customer's own environment.
10. Independent certifications and assurance
The Base44 platform (on which OrdoLux is built and hosted) holds the following independent security certifications. OrdoLux benefits from these certifications as a hosted application on the Base44 platform. The certifications cover the infrastructure, platform, and organisational controls that protect OrdoLux application data.
| SOC 2 Type II | An independent audit assessing Base44's controls against the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). The audit covers access controls, encryption, monitoring, incident management, and change management. The full report is available under NDA on request through the Base44 Security Trust Center. |
| ISO 27001 | International standard for information security management. Confirms that Base44 operates a certified Information Security Management System (ISMS) covering people, processes, and technology. The certificate is publicly available. |
| PCI DSS | Base44 holds PCI DSS certification for payment processing. This applies to payment functionality within OrdoLux that uses Base44's payment infrastructure. |
| GDPR compliance | Base44 is GDPR compliant and maintains a Data Processing Agreement available on request. |
OrdoLux can facilitate a request to Base44 for a copy of the SOC 2 Type II report under NDA if the Customer requires it for due diligence purposes. The ISO 27001 certificate is publicly available and can be provided on request.
11. Sub-processors
OrdoLux engages the following sub-processors in the provision of the Services. This list is maintained and updated in accordance with the Data Protection Addendum. The current list is also available at www.ordolux.co.uk/subprocessors/.
| Sub-processor | Role | Location | Transfer safeguard |
| Base44 (Wix.com) | Application hosting, backend infrastructure, data storage, managed authentication | United States | UK International Data Transfer Agreement / UK Addendum to the EU SCCs |
| Google Cloud (via Base44) | Underlying cloud infrastructure for OrdoLux application data | United States | UK International Data Transfer Agreement / UK Addendum to the EU SCCs |
| Microsoft (Microsoft 365 / Azure) | Customer document storage (SharePoint), email integration, calendar integration, single sign-on | United Kingdom (Customer's own tenancy) | No international transfer (data remains in Customer's UK tenancy) |
| Stripe Payments UK | Card payment processing for client invoices generated through OrdoLux | United Kingdom / Ireland | No international transfer required for UK/Ireland processing |
| Checkboard | Know Your Customer (KYC) and Anti-Money Laundering (AML) identity verification for matter onboarding | United Kingdom | No international transfer required |
| TM Group | Property search ordering and results delivery for conveyancing matters | United Kingdom | No international transfer required |
| OpenAI | AI assistant (OrdoLux "Cas") processing of matter text for drafting assistance and analysis. Each Customer may use its own OpenAI API key, under which the Customer contracts directly with OpenAI. OrdoLux facilitates the data transfer. | United States | UK International Data Transfer Agreement / UK Addendum to the EU SCCs |
Base44 maintains data processing agreements with its vendors, including approved transfer mechanisms for any international data transfers as required under Data Protection Laws. OrdoLux ensures that all sub-processors are engaged under written contracts containing materially the same data protection obligations as those set out in the Data Protection Addendum.
OrdoLux will provide the Customer with at least 30 days' notice of any addition or replacement of a sub-processor, in accordance with paragraph 5 of the Data Protection Addendum, and the Customer may exercise its rights under that paragraph.
12. Data residency and international transfers
OrdoLux application data is stored on Base44 infrastructure located in the United States. International transfers of Protected Data are governed by paragraph 7 of the Data Protection Addendum and effected using the Lawful Safeguards described therein, including the UK International Data Transfer Agreement and/or the UK Addendum to the EU Standard Contractual Clauses.
Customer documents stored in the Customer's own Microsoft 365 / SharePoint tenancy are not subject to any international transfer initiated by OrdoLux, as they remain within the Customer's own Microsoft environment.
Where sub-processors process Protected Data outside the United Kingdom, the applicable transfer safeguard is identified in the sub-processor table in section 11.
13. Backups and disaster recovery
- Customer documents: Stored in the Customer's own Microsoft 365 / SharePoint tenancy, subject to Microsoft's own backup and disaster recovery arrangements (including geo-redundant storage).
- OrdoLux application data: Backed up nightly to the Customer's own SharePoint site as CSV files, providing the Customer with a local, accessible copy of structured data within their own Microsoft environment at all times. This means that even in a worst-case scenario, the Customer's data is already in their own possession.
- Platform resilience: Base44 provides business continuity and disaster recovery for the hosting platform, including infrastructure redundancy and regular backup testing as part of its SOC 2 Type II controls.
- Recovery objectives: Base44's SOC 2 Type II audit covers availability and recovery controls, including backup testing and recovery procedures.
14. Review and updates
OrdoLux may update this Information Security Addendum from time to time to reflect changes in infrastructure, certifications, sub-processors, or security practices. Material changes will be communicated to the Customer in accordance with the Agreement.