
Security & Compliance at Lighthouse
Protecting Your Data by Design
Sensitive and regulated data is central to modern legal work. Protecting it is fundamental to how Lighthouse designs our technology, operates our infrastructure, and delivers our services.
Our security program combines independently validated controls, secure global infrastructure, continuous monitoring, and dedicated security and compliance expertise to protect client data throughout its lifecycle.
From eDiscovery to AI-enabled workflows, our teams continuously evolve our controls to address emerging threats, changing regulations, and new technologies while protecting data confidentiality, integrity, and availability.
24x7 Security Monitoring
Production infrastructure activity is centrally collected, secured, and monitored for anomalies by a 24/7/365 security operations center, supported by SIEM logging, Managed Detection and Response (MDR), and intrusion detection and prevention controls.
100+ Years Combined Experience
Our dedicated compliance and security teams comprises experts with over a century of combined experience. Their backgrounds include litigation, military, cybersecurity, and intelligence, bringing deep expertise to security, privacy, and risk management.
Secure AI by Design
Client data is not used to train or refine general-purpose generative AI models. AI resources use secure, isolated environments with role-based access, monitoring, audit trails, human review, and safeguards for prompts and outputs.
Security & Compliance Across Lighthouse
Our security and compliance program provides a consistent foundation across the solutions and environments Lighthouse manages, including our administration of Relativity aiR. Lighthouse maintains ISO 27001, SOC 2 Type II, and HIPAA-aligned controls and undergoes annual third-party penetration testing.
We monitor legislative and regulatory changes and maintain privacy practices designed to support requirements including GDPR and CCPA.

Data Protection
Lighthouse applies layered technical and process controls to protect client data and restrict access to authorized users. How these controls are implemented depends on the solution and infrastructure supporting your environment.
- Least-privilege access minimizes unnecessary data access and handling
- Technical and process controls protect identities, accounts, and access
Robust Physical Security
Geographically dispersed co-located data centers are SOC 2 or ISO 27001 certified and use layered physical and environmental safeguards.
- Access monitoring and logging
- Caged and locked server racks
- Audited keycard and biometric access controls
- Geo-redundant facilities
- Continuous power supply
- Advanced fire suppression

Security by Solution
Lighthouse combines Lighthouse-managed security controls with Microsoft Azure cloud infrastructure. Client data is logically segregated, encrypted at rest and in transit, and protected through identity and access controls, network isolation, secure key management, and continuous threat monitoring.
For generative AI workflows, LighthouseIQ leverages foundational large language models delivered through Azure infrastructure.
Lighthouse combines Lighthouse-managed security controls with Microsoft Azure cloud infrastructure. Client data is logically segregated, encrypted at rest and in transit, and protected through identity and access controls, network isolation, secure key management, and continuous threat monitoring.
The Spectra back end operates within infrastructure managed by Lighthouse using layered network, access, data protection and operational controls appropriate to Lighthouse-managed infrastructure.
Lighthouse-hosted solutions, including Relativity Server and the Spectra back end, operate within infrastructure managed by Lighthouse. These environments use layered network, access, data protection, and operational controls appropriate to Lighthouse-managed infrastructure.
- Secure transfer and chain-of-custody controls are applied as appropriate to the solution path
- Regional hosting and data-residency controls vary by solution path and client requirements
Physical Security
For Lighthouse-hosted environments, geographically dispersed co-located data centers use layered physical and environmental safeguards. These facilities are SOC 2 or ISO 27001 certified.
- Access monitoring and logging
- Caged and locked server racks
- Audited keycard and biometric access controls
- Geo-redundant facilities
- Continuous power supply
- Advanced fire suppression
Lighthouse applies its security and compliance program to how we administer and deliver services within Relativity aiR. The underlying Relativity aiR cloud infrastructure is operated and secured by Relativity, while Lighthouse maintains controls governing our administration of the environment, access, workflows, and handling of client data.
Security Starts with Our People
Dedicated security, compliance, and privacy professionals support data privacy, security engineering and architecture, and strategic information risk management.
Dedicated Security & Compliance Teams
Dedicated Data Privacy Officer (DPO)
Background Checks, Confidentiality Agreements, and Ongoing Cybersecurity, AI, and Privacy Training for Personnel
Get in Touch
We welcome your due diligence. Use this space to request compliance certificates, ask about our data governance practices, or inquire about our security frameworks.


