Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Join this August 11 webinar to explore practical strategies for managing cloud complexity and AI-driven workloads →

STAR Registry Listing for

LexIQ v2

LexIQ v2

LexIQ v2 is an AI-powered legal platform purpose-built for the Colombian legal market. It assists law firms and legal professionals with AI-assisted case management, document analysis, and legal research grounded in a curated corpus of Colombian jurisprudence, statutes, and legal doctrine.

The platform is built on three architectural pillars: a 100% microservices architecture, agentic AI workflows, and native Model Context Protocol (MCP) integration. Retrieval-Augmented Generation (RAG) with hybrid search delivers source-cited answers, with explicit confidence indicators to mitigate hallucination risk.

Security and compliance are foundational: HashiCorp Vault for secrets management, TLS 1.3 in transit and AES-256 at rest, OWASP ASVS L2 alignment, role-based access control with MFA for privileged roles, immutable audit logging, and compliance with Colombia's Habeas Data law (Ley 1581/2012) and GDPR. AI providers operate under Zero Data Retention (ZDR) agreements — no client data is used to train third-party models.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about LexIQ v2
Listed Since: 05/28/2026

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed 2 months ago, on May 28, 2026.