Skip to main content

Lexful Data Security & Privacy FAQ

FAQ about data security and data privacy at Lexful.

Written by Jeremiah Hendrickson

At Lexful, we take data security and privacy very seriously. You can find our core principles we build the Lexful platform on below.

Key Points:

1. Zero Training, Zero Sharing By Design

Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode, which means your documentation passes through our AI engine for analysis and generation but is never stored, logged, or used to improve the underlying models. What happens in your tenant, stays in your tenant.


2. Complete Multi-Tenant Isolation

Each MSP operates in a completely isolated environment with dedicated encryption keys and zero-trust security boundaries. Your client data physically cannot access another tenant's environment, it's architectural segregation, not just policy. Think of it like separate bank vaults, not separate folders in the same vault.


3. Data Never Leaves the AWS Backbone

When you use Lexful's AI features, your prompts and data are processed through AWS meaning your information never touches the public internet and stays within the secure AWS network. We use AWS's commitment that customer data remains within your region and is automatically encrypted in transit (TLS) and at rest.


4. Built for MSP Compliance from Day One

Unlike legacy platforms retrofitting AI features, Lexful was architected from the ground up with zero-trust security and compliance frameworks (SOC 2, GDPR, FIPS). Our multi-tenant architecture includes granular RBAC, comprehensive audit logging, and data residency controls - ensuring your documentation meets your clients' compliance requirements without compromising AI capabilities.


FAQs

AI & Data Training

Q: Is my data used to train Lexful's AI models or any third-party AI models?

No. Your data is never used to train AI models, period. Lexful uses AWS foundation models in inference-only mode. This means:

  • Your documentation is analyzed by AI to provide insights and generation capabilities

  • Your data passes through the AI engine temporarily for processing only

  • Zero data is stored, logged, or used to improve the underlying AI models

  • AWS contractually commits that customer data will not be used for model training

  • Lexful does not use general-purpose chatbots; instead it relies on enterprise-grade AWS models with strict no-training guarantees, the same infrastructure highly-regulated companies use for sensitive data.

Bottom line: What happens in your tenant stays in your tenant. Your competitive advantage and client information remain exclusively yours.


Multi-Tenant Security

Q: How does Lexful prevent my data from being accessed by other MSPs using the platform?

Complete architectural isolation. Each MSP operates in a fully segregated environment with:

  • Dedicated encryption keys - Cryptographically separate from all other tenants

  • Zero-trust security boundaries - Your data physically cannot access another tenant's environment

  • Separate database instances - Not just separate tables, but isolated data stores

  • Independent access controls - Permissions scoped exclusively to your organization

Think of it like this: Separate bank vaults, not separate folders in the same vault. Even if another tenant's security were compromised, they have zero access to your environment.


Data Transmission & Storage

Q: Where does my data go when I use Lexful's AI features?

Your data never leaves the AWS secure backbone. When you use AI-powered search or documentation generation:

  1. Encrypted in transit - All data transmission uses TLS 1.3 encryption

  2. Processed via AWS - Your data never touches the public internet

  3. Stays within your region - Data is processed in your designated AWS region

  4. Encrypted at rest - All stored data uses AWS KMS encryption with your customer-managed keys

Network security: AWS endpoints are accessed through private VPC connections, ensuring end-to-end security without internet exposure.


Data Ownership & Control

Q: Who owns my documentation and data?

You own 100% of your data. Lexful's terms are unambiguous:

  • You retain complete ownership of all documentation, configurations, and client data

  • You control access through granular role-based permissions (RBAC)

  • You manage retention - Export or delete your data at any time

Data portability: Your data is never locked in proprietary formats. Export capabilities ensure you can migrate at any time.


Compliance & Certifications

Q: What compliance frameworks does Lexful support?

Built for compliance from day one. Lexful's architecture supports:

  • SOC 2 Type II - Currently in progress, completion Q2 2026

  • GDPR compliant - Full compliance with EU data protection regulations

  • Data residency controls - Keep data within specified AWS geographic regions

  • Comprehensive audit logging - Track all access and changes for compliance reporting

MSP-specific: Our multi-tenant architecture ensures you can meet your end-clients' compliance requirements without compromising on AI capabilities.


Infrastructure & Reliability

Q: What security measures protect the Lexful platform itself?

Enterprise-grade security as standard:

Infrastructure Security:

  • AWS infrastructure with 99.99% uptime SLA

  • Automated backups with point-in-time recovery

  • Disaster recovery procedures with <4-hour RTO

Application Security:

  • Penetration testing by third-party security firms

  • Automated vulnerability scanning

  • Security patch management within 48 hours of critical CVEs

Access Security:

  • SSO support for centralized identity management

  • Multi-factor authentication (MFA) required for admin accounts

  • Zero-trust network architecture with least-privilege access

Monitoring:

  • 24/7 security monitoring and threat detection

  • Real-time alerting for anomalous behavior

  • Comprehensive audit trails for all system activities


Data Deletion & Retention

Deletion and retention requests are currently handled as manual support requests. Customer facing capabilities will be developed as part of SOC2 compliance.

Q: What happens to my data if I stop using Lexful?

You maintain control through the entire lifecycle:

  • During service: You can delete documents, clients, or entire data sets at any time (SOC2 roadmap)

  • Upon termination: Your data is available for export for 30 days post-cancellation

  • After 30 days: All data is permanently deleted from production systems

  • After an additional 30 days: All data is purged from backups and cannot be recovered

AWS Bedrock data: Any prompts or AI interactions are not stored and are automatically purged within 30 days per AWS's data retention policy.


Third-Party Access

Q: Does Lexful share my data with any third parties?

Minimal third-party access with strict controls:

Subprocessors we use:

  • AWS (infrastructure hosting) - Subject to AWS Data Processing Addendum

  • Stytch (authentication) - Only processes user credentials, not documentation

  • Userpilot (analytics) - Only receives anonymized usage metrics, no client data

What we NEVER do:

  • Sell or monetize your data

  • Share data with AI model providers for training

  • Allow third-party access to your documentation

Transparency: Our complete list of sub-processors is available in our Data Processing Addendum upon request.

Did this answer your question?