Security Information
How we protect information, described at a high level.
Our approach
We apply technical and organisational measures appropriate to the service, the systems involved and the sensitivity of the data. No method of transmission or storage is completely secure.
Controls we operate
- Encryption of data in transit, and at rest where appropriate.
- Role-based access and least-privilege principles.
- Authentication controls, with multi-factor authentication where the risk assessment requires it.
- Logging and monitoring of relevant security events.
- Backup and recovery processes proportionate to the service.
- Supplier and subprocessor due diligence and contractual controls.
- Incident-response and escalation procedures.
Where we process
Lexura runs on Amazon Web Services in the EU, region eu-west-2 (London). We do not claim ISO 27001 certification of our own. We do not train models on customer contracts.
Subprocessors
- Amazon Web Services EMEA (hosting, storage, email delivery) — eu-west-2.
- Stripe (payments).
- The large-language-model provider configured for analysis (currently OpenAI API, called from eu-west-2).
Retention
Uploaded contracts and generated outputs are deleted automatically after 90 days, or earlier on request (account deletion). This is a calendar-day lifecycle, not deletion immediately after a review.
Processing agreement
For a data processing agreement (AVV/DPA), email info@lexura.solutions. We will provide the current AVV. Customer contracts are not used to train models.
© 2026 · Lexura · All rights reserved