Trust Center

Trust, in one place

Everything a security or procurement team needs to evaluate Lither: our compliance posture, the controls we run, and the documents we sign — presented honestly and kept current.

Compliance posture

We publish where we actually stand. Items marked Planned are on our roadmap and not yet in force — we will never present them as achieved.

Live
GDPR

Aligned with EU data protection law, with a signed DPA available to every customer.

Live
EU data residency

Service data and our managed database stay in the EU (Frankfurt, Amsterdam).

Live
DPA

A Data Processing Agreement is available for every customer on request.

Live
Sub-processor transparency

A published sub-processor list, kept current as our vendors change.

Live
Audit trail & monitoring

Platform-wide audit logging, health monitoring, alerting, and a public status page.

Planned
SOC 2 Type II

Controls are mapped and in place; a formal independent audit is on our roadmap.

Planned
ISO 27001

Information-security management aligned to the standard; certification is planned.

Planned
Independent penetration test

Third-party testing is planned; we complete security questionnaires today.

Security controls

The controls below are live in the platform today.

Identity & access

  • Single sign-on: SAML 2.0 and OIDC (Google, GitHub, Microsoft Entra)
  • SCIM 2.0 provisioning and de-provisioning from your IdP
  • Native two-factor authentication (TOTP) with backup codes
  • Enforced MFA and enforced SSO policies, per organization
  • Role-based access control with least privilege
  • IP allow-lists to restrict where your workspace can be reached

Data protection

  • Encrypted in transit (TLS) and at rest
  • Dedicated encrypted secret vault with key rotation
  • EU data residency (Frankfurt, Amsterdam)
  • Strict multi-tenant isolation, reviewed regularly
  • Configurable data retention with automatic deletion
  • Regular encrypted backups

Monitoring & audit

  • Comprehensive, tamper-evident audit trail
  • Audit-log export (CSV / JSON) for your records
  • Real-time SIEM streaming over signed webhooks
  • Health monitoring, alerting, and a public status page
  • Login-session visibility and remote revocation

AI governance

  • AI agents run under scoped identities with explicit permissions
  • Governance policies, content moderation, and approval gates
  • An instant kill switch for any agent
  • AI asset inventory with risk tiers
  • Full run-trace and violation logging

Where we stand on certification

Lither runs on EU infrastructure (DigitalOcean, Frankfurt and Amsterdam), and your service data stays within the EU. DigitalOcean maintains SOC 2, ISO 27001 and C5 certification for the underlying data centres. Lither itself does not currently hold SOC 2 or ISO 27001 certification — those are on our roadmap. We are glad to walk through our controls, complete your security questionnaire, and provide our DPA.

To report a security vulnerability, email security@lither.app. We support responsible disclosure and will work with you to resolve verified issues.

Running a security review?

We'll share our controls, complete your questionnaire, and provide our DPA.