This statement describes how The Ethical Lawyer Network approaches privacy and regulatory compliance, the technology platform on which the TELN website is built, and the independently audited security controls that platform maintains. It is published for member firms, prospective members, referral partners, and members of the public who interact with teln.law.
Our Commitment to Compliance
The Ethical Lawyer Network ("TELN," "we," "us") is a Wyoming corporation operating a legal services and ethics platform. Compliance is not a department at TELN; it is the condition on which the network operates. Every process we run — victim identification, verification, documentation, and the non-attorney administrative services we provide to member firms — is designed to be described accurately, evidenced in writing, and reviewed on request.
Our compliance posture rests on four commitments:
- Accurate description. We describe what we do in verifiable terms. We do not advertise outcomes, guarantee results, or characterize our services as legal advice.
- Lawful data handling. Personal information is collected for identified purposes, used only for those purposes, restricted to personnel who need it, and retained no longer than the purpose and applicable law require. Where a source of data carries a statutory use restriction — the Driver's Privacy Protection Act being the clearest example — that restriction governs the entire downstream workflow.
- Documented process. Verification steps, sources, and decisions are recorded so that a member firm, a regulator, or an auditor can reconstruct how a file was assembled.
- Accountable vendors. We select technology providers that publish their control environment and submit it to independent audit, and we hold our own configuration of those platforms to the same standard of care.
Compliance obligations change. This statement is reviewed at least annually and updated when our platform, our processes, or applicable law materially change.
Privacy
Privacy is the discipline behind most of what appears in this statement. TELN handles two broad categories of personal information: routine website data from visitors and prospective members, and sensitive intake and verification data concerning individuals who may have been harmed and whose files are prepared for review by member firms. The second category is treated as the more protected of the two at every stage.
Principles we apply
- Purpose limitation. Information collected for verification is used for verification. It is not repurposed for marketing, sold, rented, or licensed to data brokers.
- Data minimization. We collect the fields required to verify identity, incident, and eligibility — not everything a source makes available.
- Access on a need-to-know basis. Access to intake and verification records is role-based and limited to personnel and member firms with a legitimate need. Platform roles, single sign-on, and multi-factor authentication are used to enforce this.
- Confidentiality of the individual. Individuals who contact TELN or whose information is verified are not treated as a commodity. Their information moves to a member firm for review under defined terms, or it does not move at all.
- Transparency and rights. Individuals may ask what we hold, ask us to correct or delete it, and receive a substantive response. The mechanics of those rights, the categories of information involved, and the applicable state and international frameworks are set out in full in the TELN Privacy Statement.
The Privacy Statement published at teln.law governs and controls in the event of any inconsistency with the summary above. Privacy-specific requests should be directed to privacy@teln.law.
Our Use of Lovable and Base44 Platform
The TELN website and the member-facing applications behind it are built and hosted on Lovable and Base44, application development and hosting platforms. We selected Lovable and Base44 deliberately, and security posture was part of the selection.
Building on an audited platform means the controls that protect our site are not improvised. Infrastructure hardening, encryption, monitoring, incident response, patching, and physical data center security are maintained by an organization whose control environment is examined by independent auditors and tested by third-party security firms. That is a materially stronger foundation than a bespoke, self-administered stack of comparable cost.
It also means our compliance obligations are shared rather than delegated. Lovable and Base44 secures the platform; TELN is responsible for how TELN configures and uses it.
Lovable and Base44's Compliance Posture
The following is drawn from the security and compliance information Lovable and Base44 publishes at base44.com/security and https://trust.lovable.dev/ in its platform documentation, current as of the effective date of this statement. TELN restates it here for the convenience of member firms conducting vendor diligence; it is Lovable's and Base44's representation of its own program, and firms requiring primary evidence should request audit reports directly through the vendor.
| Control area | Base44's published position |
|---|---|
| SOC 2 Type II | Independent audit of the design and operating effectiveness of Base44's security controls. |
| ISO/IEC 27001 | Certified information security management system against the international standard. |
| GDPR | Alignment with EU data protection standards; a Data Processing Agreement is available on request. |
| Payments | Payment processing handled through PCI DSS-certified providers. |
| Encryption | TLS 1.2 or higher in transit; AES-256 at rest, extending to backups. |
| Monitoring | A 24/7/365 Security Operations Center powered by SIEM technology. |
| Incident response | A dedicated Security Incident Response Team operating under a formal Incident Response Plan and Security Incident Management Policy. |
| Access control | Role-based workspace permissions, OIDC single sign-on with enterprise enforcement, IP allowlisting, and two-factor authentication. |
| Secrets | Application credentials held in an encrypted vault reachable only from the application backend and never exposed to end users. |
| Data residency | United States by default, with alternative regions (EU, UK) available on higher-tier plans. |
SOC 2 Type II and ISO/IEC 27001 are the two attestations that matter most for diligence purposes. The first is an auditor's opinion that controls not only existed on paper but operated effectively across a defined observation period; the second is certification of the management system that keeps those controls current. Together they cover the layer of the stack that a small organization cannot credibly audit for itself.
Penetration Testing and Vulnerability Management
Certification establishes that a control framework exists. Penetration testing establishes whether it holds under attack, and it is the part of a vendor's program we monitor closely.
Both Lovable and Base44 state that their platforms are subject to regular penetration testing performed by both internal security teams and independent third-party firms, conducted under OWASP methodologies — the industry-standard framework for identifying injection flaws, broken authentication and access control, misconfiguration, and the other categories that make up the majority of real-world web application compromise.
TELN's Position as a Platform User
TELN systems operate within the security environments of a SOC 2 Type II-audited and ISO/IEC 27001-certified platforms, and inherits the infrastructure, encryption, monitoring, and incident-response controls that environment provides. TELN uses Lovable and Base44 for its system hosting and processing.
The controls that remain ours are the ones we exercise:
- Data access rules. Record-level permissions are configured so that member firms, staff, and applicants see only the records their role requires. These rules are reviewed when roles or workflows change.
- Least privilege and account hygiene. Administrative access is limited, multi-factor authentication is required, and accounts are removed promptly when a person or firm leaves the network.
- Pre-publication review. Changes to member-facing applications are reviewed against permission settings and platform security checks before release.
- Vendor review. Providers that touch personal information are assessed before adoption and reassessed when their terms or subprocessors change. Data processing agreements are executed where the relationship calls for one.
- Retention and disposal. Records are retained per our published schedule and disposed of securely at the end of their retention period.
- Incident escalation. If a security event affecting TELN data occurs, whether it originates with us or with a provider, we investigate, notify affected parties and regulators as required by applicable law, and document what happened and what changed as a result.
Member firms performing vendor diligence on TELN should understand the arrangement in these terms: the platform layer is independently audited and continuously tested; the application layer is configured, reviewed, and documented by TELN; and both layers are open to reasonable inquiry.
Subprocessors and Data Location
TELN data hosted on the Lovable and Base44 platforms reside in the United States by default. Lovable and Base44 publish a current subprocessor directory at https://trust.lovable.dev/ and base44.com/dpa/exhibitc.
TELN engages additional providers of its own for functions such as email, document management, and payment processing. A current list of TELN's own service providers, and the categories of information each receives, is available to member firms on request to compliance@teln.law and is summarized in the TELN Privacy Statement.
Inquiries, Diligence Requests, and Reporting
We would rather answer a question than have someone assume the answer. Compliance inquiries, vendor diligence questionnaires, requests for documentation of our verification process, and reports of suspected security or ethical concerns should be directed to:
We acknowledge compliance inquiries within five business days. Requests concerning personal information, individual privacy rights, or data subject access should instead be sent to privacy@teln.law, where they are logged and tracked against the statutory response deadlines described in the Privacy Statement.
If you believe you have identified a security vulnerability affecting a TELN property, please report it to compliance@teln.law and refrain from accessing, altering, or retaining any data that is not your own. Vulnerabilities in the underlying Base44 platform may also be reported through Base44's bug bounty program.
The Ethical Lawyer Network is a legal services and ethics platform. It is not a law firm and does not provide legal advice. Members are not purchasing cases or legal claims. All fees are for victim identification, verification, documentation, and non-attorney administrative services.
Compliance Statement · Edition 2026 · TELN.LAW
