Trust & Compliance Center

Security and compliance, by architecture.

LPS is built so that the most sensitive conversations never leave the device or the customer's own boundary. That gives us the strongest possible starting point - and a clear, honest roadmap to formal certification across every market we serve. Here is exactly where we stand today, and where we are headed.

In place Live today On the way Actively pursuing

Compliance is not one-size-fits-all

A consumer therapist, a regulated enterprise, and a government agency answer to different rules. LPS meets each where they are - the same on-device core, a different compliance envelope per market.

B2C

Clinicians, therapists, lawyers - mobile apps
In place today
  • 100% on-device processing - audio and transcripts never leave the phone
  • Encryption at rest on device (AES-256) + TLS in transit for account metadata
  • GDPR & CCPA aligned by design; no content in the cloud to breach
  • Google Play Data Safety disclosure; one-tap account & data deletion
On the way
  • HIPAA formal posture for US clinical users
  • SOC 2 Type II & ISO 27701 privacy certification

B2B

Regulated enterprises - in-VPC / AWS Marketplace
In place today
  • Runs inside the customer's own VPC - data never crosses your boundary
  • Role-based access control, audit logging, encryption in transit & at rest
  • No vendor access to customer content; zero marginal token cost
  • Data Processing Agreement (DPA) available on request
On the way
  • SOC 2 Type II & ISO/IEC 27001 certification
  • HIPAA BAA program; AWS Marketplace listing with EDP eligibility

B2G

Government & defense - air-gapped / on-prem
In place today
  • Combat-proven, air-gapped deployments - fully offline, sovereign
  • Runs in secure spaces / at the customer facility; cleared personnel
  • Complete data residency - nothing leaves the enclave
On the way
  • FedRAMP authorization (US) & DoD Impact Level IL4 / IL5
  • ISO/IEC 27001; national defense security standards per country

Frameworks & certifications

Click any framework for what it means, where LPS stands, and which markets it serves. We show status honestly: a green check is in place today; an amber mark is on our active roadmap.

Security controls

The specific safeguards behind the frameworks. Expand any category to see the individual controls and their status.

Documents & resources

Public documents are linked directly. Private materials are shared under NDA - verify a work email to unlock them.

Subprocessors

Because processing is on-device (B2C) or in your own environment (B2B/B2G), our subprocessors only ever touch account metadata - never meeting audio, transcripts or reports.

SubprocessorPurposeData handledLocation
CloudflareSite & API edge hosting, DNS, WAFAccount metadata, request logsGlobal edge
LemonSqueezy (Merchant of Record)Billing & paymentsName, email, billing detailsUS / EU
Cloudflare Email / ResendTransactional emailName, emailUS / EU
Google Play / Apple App StoreApp distribution & billingStore account, purchase tokenGlobal

Meeting content is never sent to a subprocessor. On-device AI runs locally; there is no cloud inference on customer conversations.

Need something specific?

Security questionnaires, a DPA, our architecture whitepaper, or a deployment review for your compliance team - we turn these around fast.

Contact our security team

Last reviewed: this page reflects our current posture and is updated as certifications progress.