Trust, in one place
Everything a security or procurement team needs to evaluate Lither: our compliance posture, the controls we run, and the documents we sign — presented honestly and kept current.
Compliance posture
We publish where we actually stand. Items marked Planned are on our roadmap and not yet in force — we will never present them as achieved.
Aligned with EU data protection law, with a signed DPA available to every customer.
Service data and our managed database stay in the EU (Frankfurt, Amsterdam).
A Data Processing Agreement is available for every customer on request.
A published sub-processor list, kept current as our vendors change.
Platform-wide audit logging, health monitoring, alerting, and a public status page.
Controls are mapped and in place; a formal independent audit is on our roadmap.
Information-security management aligned to the standard; certification is planned.
Third-party testing is planned; we complete security questionnaires today.
Security controls
The controls below are live in the platform today.
Identity & access
- Single sign-on: SAML 2.0 and OIDC (Google, GitHub, Microsoft Entra)
- SCIM 2.0 provisioning and de-provisioning from your IdP
- Native two-factor authentication (TOTP) with backup codes
- Enforced MFA and enforced SSO policies, per organization
- Role-based access control with least privilege
- IP allow-lists to restrict where your workspace can be reached
Data protection
- Encrypted in transit (TLS) and at rest
- Dedicated encrypted secret vault with key rotation
- EU data residency (Frankfurt, Amsterdam)
- Strict multi-tenant isolation, reviewed regularly
- Configurable data retention with automatic deletion
- Regular encrypted backups
Monitoring & audit
- Comprehensive, tamper-evident audit trail
- Audit-log export (CSV / JSON) for your records
- Real-time SIEM streaming over signed webhooks
- Health monitoring, alerting, and a public status page
- Login-session visibility and remote revocation
AI governance
- AI agents run under scoped identities with explicit permissions
- Governance policies, content moderation, and approval gates
- An instant kill switch for any agent
- AI asset inventory with risk tiers
- Full run-trace and violation logging
Documents & resources
Where we stand on certification
Lither runs on EU infrastructure (DigitalOcean, Frankfurt and Amsterdam), and your service data stays within the EU. DigitalOcean maintains SOC 2, ISO 27001 and C5 certification for the underlying data centres. Lither itself does not currently hold SOC 2 or ISO 27001 certification — those are on our roadmap. We are glad to walk through our controls, complete your security questionnaire, and provide our DPA.
To report a security vulnerability, email security@lither.app. We support responsible disclosure and will work with you to resolve verified issues.
Running a security review?
We'll share our controls, complete your questionnaire, and provide our DPA.