This page explains how Lexful protects your data. The certifications, policies and the SOC 2 Type II report are available through the Trust Center.
Key points
1. Zero training, zero sharing by design
Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode: your documentation passes through the AI engine for analysis and generation but is never stored, logged, or used to improve the underlying models. What happens in your tenant stays in your tenant.
2. Full tenant isolation
Each MSP's data sits in its own database schema behind zero-trust security boundaries, with encryption keys dedicated to its tenant and access controls scoped only to its organization. Isolation is architectural, not just policy: a compromise of another tenant cannot reach your environment.
3. Data never leaves the AWS backbone
Your prompts and data are processed inside AWS and never touch the public internet. Everything is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Data is hosted in the United States today; an EU region is in progress as of October 2026.
4. Built for MSP compliance from day one
Lexful was architected from the ground up for zero-trust security and compliance: SOC 2 Type II compliant and GDPR compliant, with ISO 27001 in progress for Q4 2026. Record-level role-based access control, tag-based permissions, IP allowlisting and an immutable audit trail let you meet your clients' requirements without giving up AI capabilities.
FAQs
AI & data training
Q: Is my data used to train Lexful's AI models or any third-party AI models?
No. Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode. This means:
Your documentation is analyzed by AI to answer questions and generate content
Your data passes through the AI engine for processing only and is not retained
Nothing is stored, logged, or used to improve the underlying models
AWS contractually commits that customer data will not be used for model training
Lexful does not call general-purpose chat APIs. Ask Lex runs on enterprise AWS models with strict no-training guarantees, the same infrastructure regulated industries use for sensitive workloads
Bottom line: What happens in your tenant stays in your tenant. Your competitive advantage and your clients' information remain exclusively yours.
Q: Is AI usage metered or capped?
No. AI usage is not metered today. The AI Fair Use Policy reserves the right to apply quotas or rate limits to protect the platform; average MSP usage sits well inside any future allowance.
Multi-tenant security
Q: How does Lexful keep my data separate from other MSPs on the platform?
Architectural isolation, not just policy. Each MSP operates in a segregated environment with:
A separate database schema per tenant, not shared tables
Dedicated encryption keys, cryptographically separate from every other tenant
Zero-trust security boundaries, so your data cannot reach another tenant's environment and theirs cannot reach yours
Independent access controls, with permissions scoped only to your organization
A full audit trail: every read, write, login, permission change and password reveal is logged
Think of separate bank vaults, not separate folders in one vault. If another tenant were compromised, the attacker would still have no path into your environment.
Data transmission & storage
Q: Where does my data go when I use Lexful's AI features?
It stays inside AWS. When you use Ask Lex or document generation:
Encrypted in transit with TLS 1.2 or higher on every endpoint
Processed inside AWS, never across the public internet
Hosted in the United States today, with an EU region in progress as of October 2026
Encrypted at rest with AES-256, under keys dedicated to your tenant and managed in AWS KMS
Network security: AWS Security Groups, network ACLs and AWS WAF with OWASP Top 10 protections, geo-filtering and rate limiting sit in front of the platform. Amazon Inspector, GuardDuty, CloudTrail and CloudWatch run continuously.
Q: Where exactly is my data stored?
Client and organizational data lives only within Lexful's secured AWS environment, across Amazon RDS, Amazon S3 and DynamoDB. No customer data is stored on local devices or on third-party systems outside AWS, apart from short-lived cached data during an active session.
Data ownership & control
Q: Who owns my documentation and data?
You own 100% of your data. Lexful's terms are unambiguous:
You retain complete ownership of all documentation, configurations and client data
You control access through role-based permissions down to the individual record
You can export at any time from Settings, then Exports, as an encrypted ZIP (Export organization data)
You can leave at any time and take your data with you
Data portability: exports use open formats, not proprietary ones.
Compliance & certifications
Q: What compliance frameworks does Lexful meet?
SOC 2 Type II: compliant, evaluated across Security, Availability, Processing Integrity, Confidentiality and Privacy, and audited annually. Request the report under NDA through the Trust Center
ISO 27001: in progress, targeting Q4 2026
GDPR: compliant
PCI DSS: all payments are processed by a PCI DSS compliant provider; Lexful never stores card data
Penetration testing: performed at least annually by an independent third-party security firm, alongside continuous automated vulnerability scanning
Audit logging: immutable trails for every login, view, reveal, edit and permission change, retained for at least one year, with API and SIEM export
Information security governance is led at the senior management level, with an experienced third-party cybersecurity firm providing vCISO services.
Infrastructure & reliability
Q: What protects the Lexful platform itself?
Infrastructure:
Production runs on AWS with a multi-region high-availability design and a 99.9% uptime SLA, as published on the Trust Center
Daily encrypted backups: automated RDS snapshots and real-time S3 versioning
Production backups are restore-tested at least quarterly
Recovery time and recovery point objectives are defined per critical system; the targets are available under NDA
Application security:
Annual third-party penetration testing and continuous automated vulnerability scanning
Critical security updates deployed under our Vulnerability Management Policy
Infrastructure managed as code under version control
Access security:
Single sign-on with Microsoft, Google or Microsoft Entra (SAML), and multi-factor authentication
Least-privilege, zero-trust access for every role, including Lexful's own administrative access
Optional IP allowlisting to restrict your account to approved networks (Set up IP restrictions)
Monitoring:
24/7 security monitoring and threat detection with real-time alerting
Security events correlated in a central console and escalated
Immutable audit trails for all system activity
Data deletion & retention
Q: How do I delete data, and what happens if I leave?
During service: archive records, organizations or users in the app. Archiving is a soft delete that preserves the audit trail and can be reversed. For permanent deletion of an organization or an entire account, contact support.
If you cancel:
Your data stays available for export for 30 days after termination
After the export window it is permanently removed from production systems
It is purged from backups within 90 days and cannot be recovered after that
AI prompts and responses: not retained by the model provider. Lexful adds its own zero-retention layer on top of AWS's commitment.
Third-party access
Q: Does Lexful share my data with any third parties?
Minimal, with strict controls. Lexful uses a small number of subprocessors, each bound by a data processing agreement and used only to run the service for you. The current list is available upon request.
What we never do:
Sell or monetize your data
Share data with AI model providers for training
Allow third-party access to your documentation
Transparency: our subprocessor list and Data Processing Addendum are available upon request through the Trust Center.
Reporting a concern
Q: How do I report a security issue?
See Report a Security Concern. Platform status is published at status.lexful.app.