Security & Data Protection · September 12, 2026
Protecting business data in Lysia
Lysia is built to analyze business information such as sales, inventory, product, supplier and marketing data. This page describes the security and data-protection principles currently reflected in the service and its architecture.
Company-level data isolation
Lysia is designed around separate company workspaces. Authenticated operations resolve access from the signed-in user and active company membership rather than relying on an untrusted company identifier supplied by the browser.
Controlled access
Access to company data is tied to authentication and membership. Database access policies provide an additional authorization boundary intended to prevent one company's records from being available to another company.
Protected connections and secrets
Sensitive service credentials and third-party tokens are kept on the server rather than exposed as public application configuration. Production connections use HTTPS/TLS where supported by the service infrastructure.
Controlled AI processing
When Lysia uses an external AI provider, it is designed to send the analytical context needed for the requested task while keeping authentication credentials, access tokens and authorization data out of analytical prompts unless strictly necessary for an authorized function.
Confidential business information
Non-public customer business information is treated as confidential. Lysia does not sell customer business data, and information qualifying as a trade secret is intended to receive the protections applicable to confidential information and trade secrets.
Security is an ongoing process
Lysia uses access controls, database policies, server-side validation, security-focused testing and operational safeguards as part of its development process. No internet service can promise absolute security.
Business-data confidentiality
Customer business information submitted to Lysia is treated as confidential. Customers retain their rights in the business data they provide. Lysia uses customer business information only as reasonably necessary to provide, secure and maintain the service, comply with law, prevent abuse and fulfill customer requests, subject to the applicable Terms of Use and agreements. Where Lysia acts as a processor, customer personal data is used according to documented customer instructions and agreed service purposes, not as a general license for independent product or model improvement.
Lysia does not sell customer business data. Customers should only provide information they are authorized to share. Where information qualifies as a trade secret under applicable law, Lysia intends to handle it consistently with the confidentiality protections applicable to that information.
Access and company boundaries
Lysia uses authenticated accounts and company memberships to determine which workspace a user may access. Sensitive operations are designed to derive the company boundary from authenticated server-side identity and active membership rather than from an untrusted client-supplied company ID. Database-level access policies provide an additional layer of protection.
These controls are intended to prevent cross-company access and are reviewed as new integrations, data sources and sharing features are added.
Customer-controller and Lysia-processor responsibilities
Where a customer company determines why personal data is processed through Lysia and Lysia processes that data on the customer’s behalf, Lysia may act as the customer’s data processor. In that role, Lysia processes personal data under documented customer instructions and applies the confidentiality, security, subprocessor, assistance and deletion/return obligations required by the applicable data-processing terms and law.
Lysia may separately act as controller for limited account, security, legal-compliance and service-administration information. The distinction is described in the Privacy Notice.
AI and third-party processing
Some Lysia features use external AI model providers. Lysia is designed to minimize the information sent to those providers and to keep account credentials, access tokens and authorization information out of analytical prompts unless strictly necessary for an authorized function.
AI-generated analysis is used as decision support. Lysia does not use an AI model as the authority for user permissions, company ownership or access control. Where a provider acts as a subprocessor in a customer-processing chain, Lysia addresses the relevant contractual and data-protection obligations as required by applicable law and agreements.
Uploads and connected data
Uploaded files and connected business data are processed for the company workspace associated with the authenticated user. Customers are responsible for ensuring that they have the right to provide the data they submit. Lysia’s access-control model is designed so that one customer’s data is not available to another customer through ordinary application access.
Data deletion and retention
Lysia is adding an owner-controlled company-data deletion flow. The intended process removes active company business data, derived application records and company-specific connected-service information. Where Lysia acts as processor and processing ends, deletion or return of personal data follows the applicable controller instruction, data-processing terms and legal requirements.
Deletion from active systems may not instantly remove every residual copy held in protected backups. Residual copies remain subject to the applicable backup cycle and any legal, security or dispute-resolution retention requirement and are not intended to be restored to ordinary customer use after deletion.
Security incidents
If Lysia identifies a security incident, the incident is intended to be investigated, contained and remediated, with notifications made where required by applicable law or contractual commitments. Security logging should record the information needed to investigate events without unnecessarily duplicating sensitive customer content.
Beta service
Lysia is currently in beta. Security controls continue to evolve as the product develops, and beta use should not be interpreted as a claim that Lysia holds certifications such as SOC 2 or ISO 27001 unless Lysia expressly states otherwise.
Where a beta customer entrusts personal data to Lysia for processing on its behalf, the applicable controller-processor terms should be documented before that processing begins.
Questions about security or privacy?
Use the Contact page for security, privacy or data-protection questions.
Contact Lysia →