Skip to main content
Security & Data Protection
Praxis is built with documented security controls. Praxis is not certified against any external security standard and has not completed a full conformity assessment.
Authentication
- Multi-Factor Authentication (MFA) – TOTP-based MFA with authenticator app support
- Single Sign-On (SSO) – SAML-based SSO for enterprise customers
- Session management – Configurable session timeouts with automatic logout
- Password policy – Enforced minimum complexity requirements
Access Control
Praxis uses a granular role-based access control (RBAC) system with 24 individual permissions. Roles can be assigned at the user level, and custom permission sets can be configured for enterprise deployments.
Audit Logging
Every action in Praxis is logged in the Security Audit Log, accessible from the Admin section. The audit log records:
- Login attempts (successful and failed)
- Data access and modifications
- User management changes
- Security configuration changes
- API access patterns
Data Protection
- Encryption at rest – Documents encrypted per firm on EU-hosted servers; case metadata is stored in the EU with access control
- Encryption in transit – TLS 1.3 for all connections
- Data location – Primary platform and document hosting is in the EU (Hetzner, Germany); enabled external processors and integrations follow the selected provider, region and configuration
- Data retention policies – Platform-enforced retention and deletion; the per-firm periods are set by Praxis, not in the app
- Automated backups – Daily encrypted backups: 7 storage-box snapshots, plus offsite immutable copies locked against deletion for 90 days and retained afterwards
GDPR Support
Praxis provides controls intended to support GDPR obligations. A firm's compliance depends on its configuration and use, enabled processors and integrations, and current provider evidence. Relevant controls include:
- Data export capabilities for data subject access requests
- Data deletion workflows for right-to-erasure requests
- Processing registers and data mapping
- Consent tracking and management
← Back to Documentation