At Lexful, we take data security and privacy very seriously. You can find our core principles we build the Lexful platform on below.
Key Points:
1. Zero Training, Zero Sharing By Design
Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode, which means your documentation passes through our AI engine for analysis and generation but is never stored, logged, or used to improve the underlying models. What happens in your tenant, stays in your tenant.
2. Complete Multi-Tenant Isolation
Each MSP operates in a completely isolated environment with dedicated encryption keys and zero-trust security boundaries. Your client data physically cannot access another tenant's environment, it's architectural segregation, not just policy. Think of it like separate bank vaults, not separate folders in the same vault.
3. Data Never Leaves the AWS Backbone
When you use Lexful's AI features, your prompts and data are processed through AWS meaning your information never touches the public internet and stays within the secure AWS network. We use AWS's commitment that customer data remains within your region and is automatically encrypted in transit (TLS) and at rest.
4. Built for MSP Compliance from Day One
Unlike legacy platforms retrofitting AI features, Lexful was architected from the ground up with zero-trust security and compliance frameworks (SOC 2, GDPR, FIPS). Our multi-tenant architecture includes granular RBAC, comprehensive audit logging, and data residency controls - ensuring your documentation meets your clients' compliance requirements without compromising AI capabilities.
FAQs
AI & Data Training
Q: Is my data used to train Lexful's AI models or any third-party AI models?
No. Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode. This means:
Your documentation is analyzed by AI to provide insights and generation capabilities
Your data passes through the AI engine temporarily for processing only
Zero data is stored, logged, or used to improve the underlying AI models
AWS contractually commits that customer data will not be used for model training
Lexful does not use general-purpose chatbots; instead it relies on enterprise-grade AWS models with strict no-training guarantees, the same infrastructure highly-regulated companies use for sensitive data.
Bottom line: What happens in your tenant stays in your tenant. Your competitive advantage and client information remain exclusively yours.
Multi-Tenant Security
Q: How does Lexful prevent my data from being accessed by other MSPs using the platform?
Complete architectural isolation. Each MSP operates in a fully segregated environment with:
Dedicated encryption keys - Cryptographically separate from all other tenants
Zero-trust security boundaries - Your data physically cannot access another tenant's environment
Separate database instances - Not just separate tables, but isolated data stores
Independent access controls - Permissions scoped exclusively to your organization
Think of it like this: Separate bank vaults, not separate folders in the same vault. Even if another tenant's security were compromised, they have zero access to your environment.
Data Transmission & Storage
Q: Where does my data go when I use Lexful's AI features?
Your data never leaves the AWS secure backbone. When you use AI-powered search or documentation generation:
Encrypted in transit - All data transmission uses TLS 1.3 encryption
Processed via AWS - Your data never touches the public internet
Stays within your region - Data is processed in your designated AWS region
Encrypted at rest - All stored data uses AWS KMS encryption with your customer-managed keys
Network security: AWS endpoints are accessed through private VPC connections, ensuring end-to-end security without internet exposure.
Data Ownership & Control
Q: Who owns my documentation and data?
You own 100% of your data. Lexful's terms are unambiguous:
You retain complete ownership of all documentation, configurations, and client data
You control access through granular role-based permissions (RBAC)
You manage retention - Export or delete your data at any time
Data portability: Your data is never locked in proprietary formats. Export capabilities ensure you can migrate at any time.
Compliance & Certifications
Q: What compliance frameworks does Lexful support?
Built for compliance from day one. Lexful's architecture supports:
SOC 2 Type II - Currently in progress, completion Q2 2026
GDPR compliant - Full compliance with EU data protection regulations
Data residency controls - Keep data within specified AWS geographic regions
Comprehensive audit logging - Track all access and changes for compliance reporting
MSP-specific: Our multi-tenant architecture ensures you can meet your end-clients' compliance requirements without compromising on AI capabilities.
Infrastructure & Reliability
Q: What security measures protect the Lexful platform itself?
Enterprise-grade security as standard:
Infrastructure Security:
AWS infrastructure with 99.99% uptime SLA
Automated backups with point-in-time recovery
Disaster recovery procedures with <4-hour RTO
Application Security:
Penetration testing by third-party security firms
Automated vulnerability scanning
Security patch management within 48 hours of critical CVEs
Access Security:
SSO support for centralized identity management
Multi-factor authentication (MFA) required for admin accounts
Zero-trust network architecture with least-privilege access
Monitoring:
24/7 security monitoring and threat detection
Real-time alerting for anomalous behavior
Comprehensive audit trails for all system activities
Data Deletion & Retention
Deletion and retention requests are currently handled as manual support requests. Customer facing capabilities will be developed as part of SOC2 compliance.
Q: What happens to my data if I stop using Lexful?
You maintain control through the entire lifecycle:
During service: You can delete documents, clients, or entire data sets at any time (SOC2 roadmap)
Upon termination: Your data is available for export for 30 days post-cancellation
After 30 days: All data is permanently deleted from production systems
After an additional 30 days: All data is purged from backups and cannot be recovered
AWS Bedrock data: Any prompts or AI interactions are not stored and are automatically purged within 30 days per AWS's data retention policy.
Third-Party Access
Q: Does Lexful share my data with any third parties?
Minimal third-party access with strict controls:
Subprocessors we use:
AWS (infrastructure hosting) - Subject to AWS Data Processing Addendum
Stytch (authentication) - Only processes user credentials, not documentation
Userpilot (analytics) - Only receives anonymized usage metrics, no client data
What we NEVER do:
Sell or monetize your data
Share data with AI model providers for training
Allow third-party access to your documentation
Transparency: Our complete list of sub-processors is available in our Data Processing Addendum upon request.