LexMTLexMT
ISO 27001 Aligned

Security & Privacy

How we protect your data and our platform.

Cloud Infrastructure

LexMT is hosted on Hetzner Cloud (Helsinki, Finland) — a European provider with high security standards and ISO 27001 certified data centres.

Encryption

All data in transit is encrypted with TLS 1.3. Passwords are stored using industry-standard secure hashing. All session cookies are protected against client-side access and transmitted over secure connections only.

Access Control

Admin dashboard protected by PIN. Rate limiting on all login endpoints. One-use tokens for account setup. Principle of least privilege throughout.

Data Privacy

Uploaded documents are processed in working memory only and never written to persistent storage. Query sessions are never used to train AI models.

Monitoring

Regular automated health checks. Automated daily backups with retention policy. Alerting on process failure. Process monitoring with automatic restart.

Compliance

We process your data in accordance with GDPR. A Data Processing Agreement is available for professional customers. We never sell your data.

Technical Controls

Security controls implemented across the platform.

TLS 1.3
All traffic between your browser and our servers is encrypted.
Data Encryption
Passwords stored using secure one-way hashing. Session cookies protected against client-side access.
Authentication
Email and password login. Rate limiting. One-use setup tokens.
Rate Limiting
Query and login rate limits to prevent abuse and brute force.
Automated Backups
AI database and application data backed up daily. 7-day retention with offsite storage.
Monitoring
Automated health checks at regular intervals. Process monitoring with automatic recovery.
Security Patching
Security patches applied regularly to all system components.

Standards & Compliance

The security framework we build against.

GDPR
GDPR Compliant
EU AI Act
AI Act Aware
ISO 27001 Aligned
ISO 27001 Aligned
Hetzner ISO 27001
Hetzner DPA

Sub-Processors

Third-party providers we rely on to deliver the service.

ProviderRoleLocationLegal Basis
Hetzner Online GmbHCloud HostingFinland (EU)DPA — Art. 28 GDPR
Anthropic PBCAI Model (Claude)USA (SCCs)DPA — SCCs
OpenAI LLCAI Model (GPT-4o-mini)USA (SCCs)DPA — SCCs
Resend IncTransactional EmailUSA (SCCs)DPA — SCCs
Stripe IncPayment ProcessingUSA (SCCs)PCI-DSS compliant

Responsible Disclosure

If you discover a security vulnerability in LexMT, please report it responsibly to security@lex.mt.

security@lex.mt

We respond within 48 hours. Thank you.