SOC2C

Is this your company? Buyers are checking LEAP Legal Software here. Claim leaplegalsoftware.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
LEAP Legal Software logo

LEAP Legal Software

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

LEAP Legal Software is SOC 2 Type II compliant. LEAP Legal Software also holds GDPR, PIPEDA, and SOC 3.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

LEAP enables law firms to do what they do best – practise law. Backed by 30 years of innovation, our suite of premium legal AI features are designed to meet the unique needs of law firms. LEAP AI is seamlessly integrated into a single platform that manages your entire practice - accounting, documents, & publishing. Trusted by over 65,000 lawyers worldwide

Compliance & infrastructure

Hosting
AWS

Documents

7

Subprocessors

7
  • A
    Amazon Web Services · Hosting services
    Australia, United States, Ireland, Canada and Germany
  • S
    Salesforce · Sales CRM
    EU
  • C
    Corto · Searching document content
    United States
  • L
    LawY · AI legal research assistant
    Australia & United Kingdom
  • S
    Snowflake · Data Warehouse
    EU
  • V
    Vanta · Security
    San Francisco, USA
  • S
    Sumo Logic · Cloud log management, monitoring and analytics
    AU

Compliance leadership

The person who leads LEAP Legal Software's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. LEAP Legal Software's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

SOC 2 Type 2 - Audit Complete for 2025Jun 2026

We are pleased to confirm that LEAP has successfully completed its annual SOC 2 Type 2 attestation, conducted by an independent third-party auditor. What this means: SOC 2 Type 2 goes beyond a point-in-time snapshot. Over the audit period, our controls across Security, Availability, and Confidentiality were tested against the AICPA Trust Services Criteria and verified to be operating effectively, consistently. This covers the systems and infrastructure that underpin your LEAP environment: our cloud hosting on AWS, identity and access controls, incident response, risk management and data protection practices. What we assessed: - Security -access controls, encryption, vulnerability management, and monitoring - Availability - our infrastructure resilience, backup, and disaster recovery posture - Confidentiality -how we handle and protect sensitive client data What’s next: SOC 2 Type 2 is not a one-time exercise for us. We maintain continuous monitoring and conduct annual audits as part of our commitment to your firm’s security. Our latest audit report is available to download from this page. For any security or compliance questions, our team is available at trust@leaplegalsoftware.com.

LEAP Multi-Factor Authentication EnhancementApr 2026

LEAP Software is committed to continuously enhancing the security of our platform to protect the sensitive information entrusted to us by law firms globally. As cyber threats continue to evolve, strong authentication controls remain one of the most effective safeguards against unauthorised access. As part of our ongoing security program, LEAP has expanded our Multi-Factor Authentication (MFA) capabilities to support additional industry-standard authenticator applications. In addition to the LEAP Authenticator within the LEAP Mobile app, users can now securely authenticate using trusted third-party authenticator applications, including Google Authenticator and Microsoft Authenticator. By enabling support for widely adopted authenticator platforms, LEAP provides customers with greater flexibility while maintaining strong, standards-based verification methods. These applications generate time-based one-time passcodes (TOTP), ensuring that access requires both a user’s credentials and possession of a verified device. This enhancement reflects LEAP’s continued investment in layered security controls designed to protect customer data and reduce the risk of account compromise. We will continue to review and strengthen our authentication mechanisms in line with industry best practices and emerging threat intelligence. Documentation is available on the LEAP Community pages: Australia…

LEAP's Response to the Salesloft Drift Security IncidentOct 2025

LEAP Software is dedicated to maintaining a trusted, secure platform for Lawyers globally. Given the sensitivity of information stored on our systems, we go to great lengths to keep our customer's data protected at all times. It is with that goal in mind that we share the following security update. On August 27, Salesloft released details of a security incident involving the Drift app’s integration with Salesforce. Salesforce is a third-party software solution that LEAP uses for Customer Relationship Management including customer support. The incident was announced on the Salesloft+Drift Trust Portal, with the assurance that they would be collaborating with Salesforce to contact all affected customers. Following this announcement, LEAP was notified by Salesforce that our data may have been exposed in this breach. As an immediate precaution, we: 1. Revoked all affected tokens and credentials. 2. Escalated access monitoring and security controls. 3. Began an ongoing, internal investigation. The initial findings of our investigation confirmed that a threat actor had gained unauthorised access to our Salesforce environment. No further malicious actions have been detected, but we continue to closely monitor activity. For the benefit of our customers, we have included details of what our ongoing investigation has uncovered below. ## Results of our investigation so far: We have found…

SOC 2 Type 2 Audit Report for 2024Jun 2025

LEAP is pleased to announce the availability of our SOC 2 Type 2 Audit Report for 2024. The report covers the SOC 2 Type 2 controls related to the areas of Security, Availability and Confidentiality. We are pleased to have been audited by Assurance Labs, ensuring that our controls continue to be effective in 2024. Unlike our Type I certification, which assessed our policies and procedures at a single point-in-time, Type II demands a rigorous, in-depth audit of how these controls are implemented and maintained over a period of twelve months. LEAP has demonstrated this commitment over the last 2 years in 2023 and 2024. SOC 2 is a cybersecurity compliance framework developed by the American Institute of Certified Public Accountants (AICPA), with the primary purpose of ensuring that third-party service providers store and process client data in a secure manner. SOC 2 Reports help companies achieve that goal and are considered the “gold standard” for security compliance, internal processes, and organizational compliance awareness in SaaS companies. They require periodic maintenance and can take as long as a year to obtain. These reports provide industry-wide acknowledgment that a company adheres to “trust service principles” such as Security and Confidentiality.

CVE-2025-29927: Critical Authentication Bypass Vulnerability in Next.jsApr 2025

On the 24th of March 2025 LEAP was notified that a critical vulnerability, CVE-2025-29927, had been discovered in Next.js, one of the most widely adopted web frameworks that is also used by LEAP. The flaw allows attackers to bypass authentication and other security mechanisms enforced via middleware by manipulating the `x-middleware-subrequest` header. To mitigate this vulnerability LEAP has blocked external requests containing the x-middleware-subrequest header at our Web Application Firewall (WAF) and is updating to a patched version of Next.JS, rendering us not vulnerable to CVE-2025-29927. Next.js authentication bypass vulnerability (CVE-2025-29927) | Cyber.gov.au

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is LEAP Legal Software SOC 2 compliant?
LEAP Legal Software is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is LEAP Legal Software GDPR compliant?
According to LEAP Legal Software's public trust center, LEAP Legal Software is GDPR compliant. On SOC2C this listing is Listed.
Is LEAP Legal Software PIPEDA compliant?
According to LEAP Legal Software's public trust center, LEAP Legal Software is PIPEDA compliant. On SOC2C this listing is Listed.
Is LEAP Legal Software SOC 3 compliant?
According to LEAP Legal Software's public trust center, LEAP Legal Software is SOC 3 compliant. On SOC2C this listing is Listed.
Is LEAP Legal Software SOC 2 Type I or Type II?
LEAP Legal Software is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Business & Industrial peers that completed SOC 2