Security

Security & Trust

How we protect your data: EU-hosted with EU data residency, encrypted in transit and at rest, strict role-based access, full audit logging, and GDPR alignment.

How we protect your data

Encryption

Encrypted in transit with TLS, and at rest. Secrets and credentials are held in a dedicated encrypted vault with key rotation.

Authentication & access

SAML 2.0 SSO and OIDC (Google, GitHub, Microsoft Entra), SCIM 2.0 provisioning, and native two-factor auth (TOTP). Enforced MFA/SSO, role-based access, least privilege, and IP allow-lists per organization.

EU data residency

Hosted on DigitalOcean in EU regions (Frankfurt and Amsterdam). Service data and our managed PostgreSQL database stay within the European Union.

Audit logging & monitoring

Comprehensive audit trails across the platform, with CSV/JSON export and real-time SIEM streaming, plus health monitoring, alerting, and a public status page.

Tenant isolation & AI governance

Strict multi-tenant data isolation, reviewed regularly. AI agents run under scoped identities with explicit permissions, governance and moderation controls, and an instant kill switch.

Data protection

GDPR-aligned, with a Data Processing Agreement, a published subprocessor list, and configurable data retention with automatic deletion.

Compliance

GDPR
Aligned with EU data protection law
EU residency
Service data stored in the European Union
DPA
Data Processing Agreement for every customer
Transparency
Published subprocessor list, kept current

Security practices

Pull-request code review before every change is merged
Security reviews covering access control and multi-tenant isolation
Dependency management and prompt patching of known vulnerabilities
Encrypted secret vault with key rotation, and no secrets in source code
Role-based access control and least privilege, with regular access reviews
A written incident response plan, including GDPR breach notification
Configurable data retention with automatic deletion, and regular encrypted backups
Health monitoring, alerting, and a public status page

EU-hosted infrastructure

All Lither services run on European infrastructure (DigitalOcean, Frankfurt and Amsterdam), and your service data stays within the EU. DigitalOcean maintains SOC 2, ISO 27001 and C5 certification for the underlying data centres. Lither itself does not currently hold SOC 2 or ISO 27001 certification; we are glad to walk through our controls and complete security questionnaires.

To report a security vulnerability, email security@lither.app. We support responsible disclosure and will work with you to resolve verified issues.

Have security questions?

We are happy to share our controls, complete your security questionnaire, or provide our DPA.