Skip to content
[ SECURITY ]LEGAL / 04

Security posture, stated honestly.

What we do today, how we handle your data, and what is still on the roadmap — including the things procurement teams usually have to drag out of vendors.

LAST UPDATED: AUG 2026legal@lockedinlabs.ai
[ PROCUREMENT READINESS ]

Current controls, contract gates, and roadmap—separated.

This matrix is the fastest honest buying view. A current control is observable in the product or release path. A contract-required item must be agreed before client source or delivery activates. A roadmap item is not available today.

CURRENT

Inspectable platform controls

  • TLS, edge security headers, server-side roles, and opaque HttpOnly sessions
  • Runtime-managed credentials with repository and client-bundle leak guards
  • Explicit model-provider calls, labeled offline fallbacks, and data minimization
  • Server-side role checks and scoped authorization on protected account and organization routes
CONTRACT REQUIRED

Approved engagement boundary

  • Named source access, processing, retention, egress, and deletion terms
  • Approved models, cloud, data regions, environments, and subprocessors
  • Named client and LockedIn owners, incident path, and evidence custody
  • Signed commercial, delivery, confidentiality, and intellectual-property terms
NOT ACTIVE

Enterprise assurance roadmap

  • SOC 2 Type II report
  • Enterprise SSO / SAML provisioning
  • Standard data-processing agreement
  • Region-pinned processing and published recovery objectives
01

Architecture

The platform is hosted on Netlify with TLS on every request: plain HTTP is redirected, and security headers are applied at the edge. Application roles constrain account-level operations. Formal enterprise identity, infrastructure access-review evidence, and independent control certification remain roadmap items rather than claims this page makes today.

02

Secrets handling

Repository and bundle guards reject credentials in source code and public client assets. Runtime credentials are supplied through deployment environment configuration; release policy requires site-scoped least privilege and rotation after suspected exposure. No public page, screenshot, analytics event, or application response should contain a credential.

03

Data minimization by design

We collect what the platform needs to run and nothing more (see our privacy page). The healthcare track trains on mock and synthetic data — realistic enough to learn on, containing no real patients.

The platform does not accept PHI by default, and we ask you not to paste regulated data into lessons, artifacts, or the AI mentor. If your organization needs regulated-data workflows, that requires a separate enterprise agreement with explicit data terms — talk to us first.

04

Model provider posture

Model-capable features call a configured provider only when that provider is available. Content submitted to a live assessment, prompt review, mentor, or artifact review may be processed under that provider's API terms. Scripted or offline fallbacks are labeled and cannot impersonate a verifying model result. Where providers offer API terms that exclude training on customer data, we choose them.

We do not use your artifacts to train third-party models without your explicit consent.

05

On the roadmap — stated, not claimed

We do not currently hold a SOC 2 report, and we will not imply otherwise. The items below are in active planning. If your procurement process requires one of them today, email us — we will give you a straight answer on timing rather than a reassuring slide.

[ ON THE ROADMAP ]
SOC 2 TYPE II

Audit program in planning. We do not hold a SOC 2 report today — current status available on request.

SSO / SAML

Enterprise identity integration for private programs, with provisioning.

DPA TEMPLATES

Prepare standard data-processing agreements for enterprise counsel review.

REGION-PINNED PROCESSING

Data residency options for buyers with jurisdictional requirements.

06

Vulnerability disclosure

Found something? Email security@lockedinlabs.ai with a description and reproduction steps. We aim to acknowledge reports within two business days, and we will tell you what we are doing about it.

We do not run a paid bug bounty program today, but we credit researchers who report responsibly — with their permission.

This page is informational and does not constitute legal advice.