Trust & Security

Lynctera is built for regulated environments. Security, data isolation, and AI governance are architectural properties of the platform — not policies added after deployment.

View Vanta Trust Center

Certifications & Compliance

We invest in certifications that matter to regulated procurement teams. Request our SOC 2 report and review our policies via the Vanta trust center.

SOC 2 Type II

Independently audited. Report available on request via our trust center.

ISO 42001

AI management system certification programme in progress.

GDPR

Data processing agreements, consent management, and data subject rights built into the platform.

Data Isolation

Your data never shares infrastructure with another organisation. Isolation is physical, not logical.

Per-tenant databases

Every customer gets a dedicated Azure SQL database. No shared tables, no row-level filtering, no risk of cross-tenant data exposure.

Dedicated secrets management

Tenant credentials, API keys, and certificates are stored in Azure Key Vault with per-tenant scoping. Accessed via managed identity only.

Isolated AI search indexes

Knowledge base content is indexed per tenant. No shared search infrastructure between organisations.

Regional data residency

Infrastructure hosted on Microsoft Azure in UK and EU regions. Data does not leave the specified residency boundary.

AI Governance

AI governance is enforced by the platform architecture, not by policy documents. These controls cannot be bypassed.

Full audit trail

Every AI action is logged automatically: model used, tokens consumed, cost, duration, and output. LLM decisions and tool operations are tracked on separate audit surfaces.

Rules before AI

Deterministic rules evaluate first. AI is invoked only when synthesis or judgement is required. This reduces cost, risk, and unnecessary model calls.

Human approval gates

Workflows pause at defined gates until a human approves. AI cannot publish, act, or proceed past a gate without explicit human authorisation.

Context validation

The framework blocks AI calls with incomplete context. If required information is missing, the call is rejected before it reaches the model.

Versioned AI configuration

Agent prompts, models, and parameters are version-controlled with temporal history. Any AI behaviour can be reconstructed at any point in time.

Drift monitoring

AI configuration is continuously monitored across tenants and environments. Deviations from the governed baseline are detected and reported automatically.

Infrastructure & Access

Enterprise-grade infrastructure on Microsoft Azure with zero standing access to customer data.

Azure-hosted

All services run on Microsoft Azure. Compute, storage, AI services, and networking are managed within Azure's compliance boundary.

Managed identity

No hardcoded credentials. All service-to-service authentication uses Azure Managed Identity. Secrets are retrieved from Key Vault at runtime.

Azure OpenAI only

All AI model calls route through Azure OpenAI. No data is sent to third-party AI providers. Enterprise data processing agreements apply.

WAF & network controls

Public-facing services are protected by Azure Front Door with Web Application Firewall. Backend services have network-level access restrictions.

Request our SOC 2 report

Visit our Vanta trust center to request the SOC 2 report, review our security policies, or ask a security question.