Skip to main content

Lexful Data Security & Privacy FAQ

FAQ about data security and data privacy at Lexful.

This page explains how Lexful protects your data. The certifications, policies and the SOC 2 Type II report are available through the Trust Center.

​

Key points

1. Zero training, zero sharing by design

Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode: your documentation passes through the AI engine for analysis and generation but is never stored, logged, or used to improve the underlying models. What happens in your tenant stays in your tenant.

​


2. Full tenant isolation

Each MSP's data sits in its own database schema behind zero-trust security boundaries, with encryption keys dedicated to its tenant and access controls scoped only to its organization. Isolation is architectural, not just policy: a compromise of another tenant cannot reach your environment.

​


3. Data never leaves the AWS backbone

Your prompts and data are processed inside AWS and never touch the public internet. Everything is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Data is hosted in the United States today; an EU region is in progress as of October 2026.

​


4. Built for MSP compliance from day one

Lexful was architected from the ground up for zero-trust security and compliance: SOC 2 Type II compliant and GDPR compliant, with ISO 27001 in progress for Q4 2026. Record-level role-based access control, tag-based permissions, IP allowlisting and an immutable audit trail let you meet your clients' requirements without giving up AI capabilities.

​


FAQs

AI & data training

Q: Is my data used to train Lexful's AI models or any third-party AI models?

No. Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode. This means:

  • Your documentation is analyzed by AI to answer questions and generate content

  • Your data passes through the AI engine for processing only and is not retained

  • Nothing is stored, logged, or used to improve the underlying models

  • AWS contractually commits that customer data will not be used for model training

  • Lexful does not call general-purpose chat APIs. Ask Lex runs on enterprise AWS models with strict no-training guarantees, the same infrastructure regulated industries use for sensitive workloads

Bottom line: What happens in your tenant stays in your tenant. Your competitive advantage and your clients' information remain exclusively yours.

​

Q: Is AI usage metered or capped?

No. AI usage is not metered today. The AI Fair Use Policy reserves the right to apply quotas or rate limits to protect the platform; average MSP usage sits well inside any future allowance.

​


Multi-tenant security

Q: How does Lexful keep my data separate from other MSPs on the platform?

Architectural isolation, not just policy. Each MSP operates in a segregated environment with:

  • A separate database schema per tenant, not shared tables

  • Dedicated encryption keys, cryptographically separate from every other tenant

  • Zero-trust security boundaries, so your data cannot reach another tenant's environment and theirs cannot reach yours

  • Independent access controls, with permissions scoped only to your organization

  • A full audit trail: every read, write, login, permission change and password reveal is logged

Think of separate bank vaults, not separate folders in one vault. If another tenant were compromised, the attacker would still have no path into your environment.

​


Data transmission & storage

Q: Where does my data go when I use Lexful's AI features?

It stays inside AWS. When you use Ask Lex or document generation:

  1. Encrypted in transit with TLS 1.2 or higher on every endpoint

  2. Processed inside AWS, never across the public internet

  3. Hosted in the United States today, with an EU region in progress as of October 2026

  4. Encrypted at rest with AES-256, under keys dedicated to your tenant and managed in AWS KMS

Network security: AWS Security Groups, network ACLs and AWS WAF with OWASP Top 10 protections, geo-filtering and rate limiting sit in front of the platform. Amazon Inspector, GuardDuty, CloudTrail and CloudWatch run continuously.

​

Q: Where exactly is my data stored?

Client and organizational data lives only within Lexful's secured AWS environment, across Amazon RDS, Amazon S3 and DynamoDB. No customer data is stored on local devices or on third-party systems outside AWS, apart from short-lived cached data during an active session.

​


Data ownership & control

Q: Who owns my documentation and data?

You own 100% of your data. Lexful's terms are unambiguous:

  • You retain complete ownership of all documentation, configurations and client data

  • You control access through role-based permissions down to the individual record

  • You can export at any time from Settings, then Exports, as an encrypted ZIP (Export organization data)

  • You can leave at any time and take your data with you

Data portability: exports use open formats, not proprietary ones.

​


Compliance & certifications

Q: What compliance frameworks does Lexful meet?

  • SOC 2 Type II: compliant, evaluated across Security, Availability, Processing Integrity, Confidentiality and Privacy, and audited annually. Request the report under NDA through the Trust Center

  • ISO 27001: in progress, targeting Q4 2026

  • GDPR: compliant

  • PCI DSS: all payments are processed by a PCI DSS compliant provider; Lexful never stores card data

  • Penetration testing: performed at least annually by an independent third-party security firm, alongside continuous automated vulnerability scanning

  • Audit logging: immutable trails for every login, view, reveal, edit and permission change, retained for at least one year, with API and SIEM export

Information security governance is led at the senior management level, with an experienced third-party cybersecurity firm providing vCISO services.

​


Infrastructure & reliability

Q: What protects the Lexful platform itself?

Infrastructure:

  • Production runs on AWS with a multi-region high-availability design and a 99.9% uptime SLA, as published on the Trust Center

  • Daily encrypted backups: automated RDS snapshots and real-time S3 versioning

  • Production backups are restore-tested at least quarterly

  • Recovery time and recovery point objectives are defined per critical system; the targets are available under NDA

Application security:

  • Annual third-party penetration testing and continuous automated vulnerability scanning

  • Critical security updates deployed under our Vulnerability Management Policy

  • Infrastructure managed as code under version control

Access security:

  • Single sign-on with Microsoft, Google or Microsoft Entra (SAML), and multi-factor authentication

  • Least-privilege, zero-trust access for every role, including Lexful's own administrative access

  • Optional IP allowlisting to restrict your account to approved networks (Set up IP restrictions)

Monitoring:

  • 24/7 security monitoring and threat detection with real-time alerting

  • Security events correlated in a central console and escalated

  • Immutable audit trails for all system activity

​


Data deletion & retention

Q: How do I delete data, and what happens if I leave?

During service: archive records, organizations or users in the app. Archiving is a soft delete that preserves the audit trail and can be reversed. For permanent deletion of an organization or an entire account, contact support.

​

If you cancel:

  • Your data stays available for export for 30 days after termination

  • After the export window it is permanently removed from production systems

  • It is purged from backups within 90 days and cannot be recovered after that

AI prompts and responses: not retained by the model provider. Lexful adds its own zero-retention layer on top of AWS's commitment.

​


Third-party access

Q: Does Lexful share my data with any third parties?

Minimal, with strict controls. Lexful uses a small number of subprocessors, each bound by a data processing agreement and used only to run the service for you. The current list is available upon request.

​

What we never do:

  • Sell or monetize your data

  • Share data with AI model providers for training

  • Allow third-party access to your documentation

Transparency: our subprocessor list and Data Processing Addendum are available upon request through the Trust Center.

​


Reporting a concern

Q: How do I report a security issue?

See Report a Security Concern. Platform status is published at status.lexful.app.

​

Did this answer your question?