Trust & Security
Security at Lyrion
Every action is logged against the record it touched. Approvals sit wherever your team wants them, and nothing leaves the building without a person. That is what gets a system through a security review.
What stays yours
Your controls
Systems run under the controls you already have, on your own platforms.
Your residency
Able to run inside your own environment where residency requires it.
Your record
An audit trail ready before the auditor asks.
In depth
How a system is secured
What we put in place for every system we build, from scoping to operation.
Inside the system
Audit Logging
Every action the system takes is logged against the record it touched, and the log stays with you.
Monitoring
The engineers who built the system watch it in production and answer for it when something breaks.
Data Handling
Data stays in your systems of record. Nothing is copied out to make a system work, and nothing is uploaded to us.
Role-Based Approvals
Approvals follow your own roles. A person with the right authority signs wherever your team wants a signature.
Single Sign-On
Access goes through your identity provider, so the people who can approve are the people you already manage.
Data Handling
Access Review
Every connection the system makes is listed, reviewed by your engineers and scoped to what that system needs.
Recovery
Each system has a documented way to stop, roll back and hand the work to a person.
Encryption at rest
Data the system holds is encrypted at rest, scoped per system.
Encryption in transit
Every connection between the system and your platforms is encrypted in transit.
Your Environment
Systems that run inside your own environment inherit your physical, network and access controls.
Data Privacy
Cookies
Our cookie policy is available within the privacy documents on our legal page.
Training
Nothing you give us is used to train a model.
Access Control
Least Privilege
Each system gets the access its process needs and nothing more, agreed in the written blueprint.
Logging
Security events from the system are logged and kept under your retention rules.
Credentials
Credentials are held in your environment and rotated under your policies.
Change Control
Responsible Disclosure
If you find a security issue in a system we built, tell us and it is ours until it is fixed.
Approvals for Change
No change reaches a system in production without the approval your team has set.
Development Lifecycle
Every system is built against a written blueprint that your engineers review before anything is built.
Vulnerability Management
Dependencies are tracked per system and patched by the engineers who operate it.
Operation
Continuity
Each system can be paused with the work handed back to the people who did it before.
Availability
Systems are deployed on your platforms, so they run where your critical systems already run.
Residency
Where residency requires it, the whole system runs inside your own environment.
Our Engineers
Devices
Our engineers work on managed, encrypted devices.
Access
Engineers reach a client's environment only through the access that client grants and can revoke.
Accountability
The same engineers scope, build and run each system, so responsibility never passes to a team that was not in the room.
Network
Boundaries
Systems sit behind the network boundaries you already operate.
Monitoring
Security events can be sent to the monitoring your security team already uses.
Private Connectivity
Connections to your systems of record use the private routes your team approves.
Our Company
Training
Every engineer is trained on the security and privacy obligations of the work they do.
Incident Response
A security incident has an owner, an escalation path and a person who tells you what happened.
Security Review
We support the security review your team runs before any system goes live.
Report a Vulnerability
Contact the Lyrion security team by email at contact@lyrion.io with the subject line “Responsible Disclosure.”