576 words, 10 clausesupdated September 1, 2025read 25/08/2026source
·Customer rights and shared responsibility
·Customer rights and shared responsibility 8.1
·Upon request, and at no additional cost to Customer, Legora shall provide Customer, and/or its appropriately qualified third-party representative (collectively, the "Auditor"), access to reasonably requested documentation evidencing our compliance with our obligations under this Security Addendum in the form of, as applicable a copy of our (i) ISO 27001 certificate (ii) a summary of the results of our most recently completed penetration test, and (iii) data flow diagrams for the Service (collectively with Third-Party Audits, "Audit Reports"). Where an Auditor is a third-party, such third party will be required to execute a separate confidentiality agreement with Legora prior to any audit, Pen Test, or review of Audit Reports, and Legora may object in writing to such third party if in Legora's reasonable opinion, the third party is not suitably qualified. Any such objection will require You to appoint another third party or conduct such audit, Pen Test, or review. Legora is not responsible for any expenses incurred by an Auditor in connection with any review of Audit Reports, or an audit or Pen Test. 8.1
·Upon request, and at no additional cost to Customer, Legora shall provide Customer, and/or its appropriately qualified third-party representative (collectively, the "Auditor"), access to reasonably requested documentation evidencing our compliance with our obligations under this Security Addendum in the form of, as applicable a copy of our (i) ISO 27001 certificate (ii) a summary of the results of our most recently completed penetration test, and (iii) data flow diagrams for the Service (collectively with Third-Party Audits, "Audit Reports"). Where an Auditor is a third-party, such third party will be required to execute a separate confidentiality agreement with Legora prior to any audit, Pen Test, or review of Audit Reports, and Legora may object in writing to such third party if in Legora's reasonable opinion, the third party is not suitably qualified. Any such objection will require You to appoint another third party or conduct such audit, Pen Test, or review. Legora is not responsible for any expenses incurred by an Auditor in connection with any review of Audit Reports, or an audit or Pen Test. 8.2
·It is the Customer's responsibility to ensure that it is authorized to use any Input or Customer Data with the Service and that Your usage complies with relevant legal and regulatory obligations. 8.2
·It is the Customer's responsibility to ensure that it is authorized to use any Input or Customer Data with the Service and that Your usage complies with relevant legal and regulatory obligations. 8.3
·You are responsible for managing and protecting Your credentials to access the Service. User credentials must be kept confidential and may not be shared with unauthorized parties. You must promptly report any suspicious activities related to Your account(s) (such as when You reasonably believe that credentials have been compromised). 8.3
·You are responsible for managing and protecting Your credentials to access the Service. User credentials must be kept confidential and may not be shared with unauthorized parties. You must promptly report any suspicious activities related to Your account(s) (such as when You reasonably believe that credentials have been compromised). 8.4
·You are responsible for keeping Your relevant IT systems (such as the browser You use to access the Service) up-to-date and appropriately patched. 8.4
·You are responsible for keeping Your relevant IT systems (such as the browser You use to access the Service) up-to-date and appropriately patched.