Trust center

How we handle your data

We work in healthcare, financial services, and real estate, where a mistake reaches someone real. Security and data handling are part of how the work gets done. Everything below is a control we operate today, and where we do not hold something, this page says so.

The short version

Four things that are always true

A person on every consequence

Nothing irreversible happens on its own. Merges, deploys, publishing, and spend all stop at a human approval, including when the rest of the work runs unattended.

We do not train on your data

Your code, documents, and configurations are never used to train a Lucitra model, and our model providers do not train on what we send them under our commercial terms.

Encrypted, in US regions

Data is encrypted in transit and at rest, stored in Google Cloud in US regions, and reachable only by scoped, revocable access granted per team.

Every action is logged

Actions, costs, and approvals are written to an append-only audit log with integrity hashes. The record of who approved what is not editable after the fact.

Compliance

Where we stand, stated plainly

Three of the four rows below are a yes because we operate what they ask for. SOC 2 is not, and rather than leave you to discover that in a questionnaire, it is on this page.

HIPAA

BAA available

HIPAA has no certificate to hold and no agency issues one. Compliance is a posture: signed Business Associate Agreements up and down the chain, Security Rule safeguards, minimum-necessary access, and a written breach procedure. We sign a BAA before any protected health information reaches our systems, and we hold one with every sub-processor in that path.

SOC 2 Type II

Not audited

We are not SOC 2 audited today. We do operate the controls such an audit examines: access control, encryption, audit logging, change review, and incident response. We will pursue certification when a customer procurement process requires it.

GDPR

Supported

Access, rectification, erasure, restriction, portability, and objection are all supported. Requests go to privacy@lucitra.ai and are answered within 30 days. Transfers out of the EEA, UK, and Switzerland rely on Standard Contractual Clauses.

CCPA and CPRA

Supported

California residents can request the categories and specific pieces of personal information we hold, and request deletion. We do not sell personal information and we do not share it for cross-context behavioral advertising.

Agents

What bounds an agent

The controls above are the ones every vendor is asked about. These are the ones that matter when the work is done by agents, and they are the reason we are willing to point agents at regulated systems at all.

Scoped connectors, granted per team

An agent reaches only the systems it was granted, and a grant is revocable. There is no ambient credential that every agent can see.

Isolated workspaces

Each task runs in its own workspace. Work in progress cannot reach your main branch, your production systems, or your money without passing the approval step first.

Bounded delegation

Agents assign work to other agents within a depth cap. Runaway recursion is stopped by the system rather than by a prompt asking it not to.

Enforced limits, not tracked ones

Spend and usage limits are checked before a run starts, not totalled up afterwards. A run that would exceed its budget does not begin, and there is a global stop.

Model access matched to the data

Our default execution path runs on a subscription plan, which is not covered by a BAA and is therefore never used for protected health information. Work in scope for PHI runs on first-party API or Enterprise plans covered by a signed BAA.

The reviewable artifact is the real one

You approve a diff, a citation set, or an evidence trace, not a summary of one. Review comments become structured context the agent has to answer.

Data practices

What we collect and how long we keep it

Account information

  • Name and email address
  • Organization name and role
  • Authentication records, managed by Stytch

Work data

  • Repositories, documents, and task context you bring
  • Agent configurations and approval policies
  • Diffs, findings, and other work output

Operational records

  • Audit records: actions, costs, approvals
  • Aggregate usage analytics, cookieless on the website
  • Support requests and correspondence

Retention

Data Retained for
Work data While your account is active. Deletable at any time.
Audit records While your account is active. They are your audit trail.
Account data Active, plus 30 days after deletion for recovery
Usage analytics 24 months, anonymized and aggregated
Security logs 12 months

Sub-processors

6 providers touch data, and every one of them is listed with what reaches it and where it sits. We do not sell personal data. See the full register →

Documents

The paperwork, in one place

Report a vulnerability

Send it to security@lucitra.ai and we will respond promptly. We will not pursue anyone who reports a genuine issue in good faith.

Privacy and data rights

Exercise a data right or ask how something is handled at privacy@lucitra.ai. Requests are answered within 30 days.

Security review or BAA

Questionnaires, BAAs, and DPAs go to legal@lucitra.ai. Send the questionnaire you already have rather than a new one.