Security
How we protect this website, our systems and the data our clients trust us with.
Security is part of how we design Lemma and every agent we deploy, not a later review. This page describes our current practices and will grow as our program matures.
This website
- Served only over HTTPS through a global content delivery network.
- No analytics, advertising or other third-party scripts run on the Site.
- Secrets such as API keys are stored encrypted and are never sent to your browser.
- Access to our cloud accounts is limited to the people who need it and protected by multi-factor authentication.
- Forms and AI features are rate-limited to prevent abuse.
Client engagements
- Client agents can run in the client's own cloud account or on their premises.
- Access to client systems is limited to the people working on that engagement, and reviewed when the engagement ends.
- Every agent action is recorded with its reasoning trace, so it can be audited.
- Client data is not used to train models without a written agreement.
Reporting a problem
If you think you have found a vulnerability, please follow our responsible disclosure policy or email contact@theoratix.ai.