How Lira protects your organization's data.
All data in transit is encrypted with TLS 1.2 or higher. Sensitive data at rest is encrypted with AES-256. Stored passwords use bcrypt salted hashing.
JWT-based authentication with secure token management, scoped OAuth or signed API credentials for connected services, and role-based access control.
Minimal collection, purpose limitation, and logical isolation between organizations. Your documents, transcripts and organizational data are never used to train general-purpose AI models shared with other customers. Data export on request; deletion within 30 days.
GDPR — data processing agreements, data subject rights, and Standard Contractual Clauses for international transfers. CCPA and CPRA — right to know, delete and opt out; we do not sell personal information. Our infrastructure providers maintain SOC 2 Type II; we are working toward our own SOC 2 certification.
Regular security assessments including dependency vulnerability scanning, code review, penetration testing, and static analysis in CI. A documented incident response plan. Production access restricted to authorized personnel with multi-factor authentication and least privilege.
Report potential security issues to info@liraintelligence.com. We acknowledge receipt within 48 hours and provide an initial assessment within 5 business days.