A person on every consequence
Nothing irreversible happens on its own. Merges, deploys, publishing, and spend all stop at a human approval, including when the rest of the work runs unattended.
Trust center
We work in healthcare, financial services, and real estate, where a mistake reaches someone real. Security and data handling are part of how the work gets done. Everything below is a control we operate today, and where we do not hold something, this page says so.
The short version
Nothing irreversible happens on its own. Merges, deploys, publishing, and spend all stop at a human approval, including when the rest of the work runs unattended.
Your code, documents, and configurations are never used to train a Lucitra model, and our model providers do not train on what we send them under our commercial terms.
Data is encrypted in transit and at rest, stored in Google Cloud in US regions, and reachable only by scoped, revocable access granted per team.
Actions, costs, and approvals are written to an append-only audit log with integrity hashes. The record of who approved what is not editable after the fact.
Compliance
Three of the four rows below are a yes because we operate what they ask for. SOC 2 is not, and rather than leave you to discover that in a questionnaire, it is on this page.
HIPAA has no certificate to hold and no agency issues one. Compliance is a posture: signed Business Associate Agreements up and down the chain, Security Rule safeguards, minimum-necessary access, and a written breach procedure. We sign a BAA before any protected health information reaches our systems, and we hold one with every sub-processor in that path.
We are not SOC 2 audited today. We do operate the controls such an audit examines: access control, encryption, audit logging, change review, and incident response. We will pursue certification when a customer procurement process requires it.
Access, rectification, erasure, restriction, portability, and objection are all supported. Requests go to privacy@lucitra.ai and are answered within 30 days. Transfers out of the EEA, UK, and Switzerland rely on Standard Contractual Clauses.
California residents can request the categories and specific pieces of personal information we hold, and request deletion. We do not sell personal information and we do not share it for cross-context behavioral advertising.
Agents
The controls above are the ones every vendor is asked about. These are the ones that matter when the work is done by agents, and they are the reason we are willing to point agents at regulated systems at all.
An agent reaches only the systems it was granted, and a grant is revocable. There is no ambient credential that every agent can see.
Each task runs in its own workspace. Work in progress cannot reach your main branch, your production systems, or your money without passing the approval step first.
Agents assign work to other agents within a depth cap. Runaway recursion is stopped by the system rather than by a prompt asking it not to.
Spend and usage limits are checked before a run starts, not totalled up afterwards. A run that would exceed its budget does not begin, and there is a global stop.
Our default execution path runs on a subscription plan, which is not covered by a BAA and is therefore never used for protected health information. Work in scope for PHI runs on first-party API or Enterprise plans covered by a signed BAA.
You approve a diff, a citation set, or an evidence trace, not a summary of one. Review comments become structured context the agent has to answer.
Data practices
| Data | Retained for |
|---|---|
| Work data | While your account is active. Deletable at any time. |
| Audit records | While your account is active. They are your audit trail. |
| Account data | Active, plus 30 days after deletion for recovery |
| Usage analytics | 24 months, anonymized and aggregated |
| Security logs | 12 months |
6 providers touch data, and every one of them is listed with what reaches it and where it sits. We do not sell personal data. See the full register →
Documents
Send it to security@lucitra.ai and we will respond promptly. We will not pursue anyone who reports a genuine issue in good faith.
Exercise a data right or ask how something is handled at privacy@lucitra.ai. Requests are answered within 30 days.
Questionnaires, BAAs, and DPAs go to legal@lucitra.ai. Send the questionnaire you already have rather than a new one.