Compliance is not one-size-fits-all
A consumer therapist, a regulated enterprise, and a government agency answer to different rules. LPS meets each where they are - the same on-device core, a different compliance envelope per market.
B2C
- 100% on-device processing - audio and transcripts never leave the phone
- Encryption at rest on device (AES-256) + TLS in transit for account metadata
- GDPR & CCPA aligned by design; no content in the cloud to breach
- Google Play Data Safety disclosure; one-tap account & data deletion
- HIPAA formal posture for US clinical users
- SOC 2 Type II & ISO 27701 privacy certification
B2B
- Runs inside the customer's own VPC - data never crosses your boundary
- Role-based access control, audit logging, encryption in transit & at rest
- No vendor access to customer content; zero marginal token cost
- Data Processing Agreement (DPA) available on request
- SOC 2 Type II & ISO/IEC 27001 certification
- HIPAA BAA program; AWS Marketplace listing with EDP eligibility
B2G
- Combat-proven, air-gapped deployments - fully offline, sovereign
- Runs in secure spaces / at the customer facility; cleared personnel
- Complete data residency - nothing leaves the enclave
- FedRAMP authorization (US) & DoD Impact Level IL4 / IL5
- ISO/IEC 27001; national defense security standards per country
Frameworks & certifications
Click any framework for what it means, where LPS stands, and which markets it serves. We show status honestly: a green check is in place today; an amber mark is on our active roadmap.
Security controls
The specific safeguards behind the frameworks. Expand any category to see the individual controls and their status.
Documents & resources
Public documents are linked directly. Private materials are shared under NDA - verify a work email to unlock them.
Subprocessors
Because processing is on-device (B2C) or in your own environment (B2B/B2G), our subprocessors only ever touch account metadata - never meeting audio, transcripts or reports.
| Subprocessor | Purpose | Data handled | Location |
|---|---|---|---|
| Cloudflare | Site & API edge hosting, DNS, WAF | Account metadata, request logs | Global edge |
| LemonSqueezy (Merchant of Record) | Billing & payments | Name, email, billing details | US / EU |
| Cloudflare Email / Resend | Transactional email | Name, email | US / EU |
| Google Play / Apple App Store | App distribution & billing | Store account, purchase token | Global |
Meeting content is never sent to a subprocessor. On-device AI runs locally; there is no cloud inference on customer conversations.
Need something specific?
Security questionnaires, a DPA, our architecture whitepaper, or a deployment review for your compliance team - we turn these around fast.
Contact our security teamLast reviewed: this page reflects our current posture and is updated as certifications progress.