In development · Built by the Parselex team

Your case network,
invisible to the internet.

LexZTNA is Zero-Trust Network Access for legal workloads: an encrypted device-to-cloud mesh where every session is authenticated, every device is checked, and access is granted per case — never per network.

No open ports · No flat network · No implicit trust

Product pillars

Six controls, one principle:
trust nothing by default.

Zero-trust mesh

No flat network and no VPN perimeter. Each connection is authenticated, authorized and encrypted — the mesh is invisible to anyone who is not part of a case.

Encrypted tunnels

Device-to-cloud encryption on every link. Case traffic never travels in the clear and never mixes with other tenants' traffic.

SSO / MFA + device posture

Sign-in through your identity provider with MFA. Posture checks run continuously — a device that falls out of compliance loses access mid-session.

DNS-layer DLP

Filtering and data-loss prevention enforced at the DNS layer: risky destinations are blocked before a connection is even established.

Least-privilege, per case

Network grants mirror case membership. When a lawyer leaves a matter, the network path to it closes automatically.

Global edge

Served from Cloudflare's edge network — short tunnels, low latency, and no case data exposed to the public internet.

How it works

Three steps from install to invisible.

Enroll the device

The LexZTNA client joins the mesh and receives a device identity. Nothing is reachable yet — the network is silent by default.

Authenticate with posture

SSO with MFA verifies the person; posture checks verify the device. Both must pass, and both are re-evaluated continuously.

Work, per case

The user sees only the resources their active cases grant: the case vault, the workspace, the hub. Everything else does not exist for them.

Platform context

The network layer of the Parselex platform.

LexZTNA wraps the Parselex legal stack — LexRegister case intelligence, per-case document workspaces and the multi-agent MCP Hub — in a zero-trust network fabric. The applications enforce what may be seen; LexZTNA enforces where the network can even look.

Built alongside production casework

The Parselex platform runs live legal workloads today, with 2,309 automated checks per release and per-case document isolation. LexZTNA extends that same discipline from the application layer down to the network layer.

Security first, in the open

Security architecture and benchmark documentation for the Parselex platform are public. LexZTNA design notes follow the same path: published, reviewed and verifiable.

Following the zero-trust build.

LexZTNA is in active development. Watch the roadmap and security notes on the Parselex platform site — or try the live product family today.