Systems
AI SystemsMethodWorkOperationIndustriesField Notes
Solutions
EnterpriseRegulated IndustriesProcessesIntake and ServiceDocument ReviewReconciliation
Integration
Systems of RecordModel GovernanceAudit TrailChange ControlBlueprintData Residency
Company
AboutEngagementsSecurityOversightCareersContact
EngagementsNews
Talk to UsScoping Session

Trust & Security

Security at Lyrion

Every action is logged against the record it touched. Approvals sit wherever your team wants them, and nothing leaves the building without a person. That is what gets a system through a security review.

What stays yours

  • Your controls

    Systems run under the controls you already have, on your own platforms.

  • Your residency

    Able to run inside your own environment where residency requires it.

  • Your record

    An audit trail ready before the auditor asks.

In depth

How a system is secured

What we put in place for every system we build, from scoping to operation.

Inside the system

  • Audit Logging

    Every action the system takes is logged against the record it touched, and the log stays with you.

  • Monitoring

    The engineers who built the system watch it in production and answer for it when something breaks.

  • Data Handling

    Data stays in your systems of record. Nothing is copied out to make a system work, and nothing is uploaded to us.

  • Role-Based Approvals

    Approvals follow your own roles. A person with the right authority signs wherever your team wants a signature.

  • Single Sign-On

    Access goes through your identity provider, so the people who can approve are the people you already manage.

Data Handling

  • Access Review

    Every connection the system makes is listed, reviewed by your engineers and scoped to what that system needs.

  • Recovery

    Each system has a documented way to stop, roll back and hand the work to a person.

  • Encryption at rest

    Data the system holds is encrypted at rest, scoped per system.

  • Encryption in transit

    Every connection between the system and your platforms is encrypted in transit.

  • Your Environment

    Systems that run inside your own environment inherit your physical, network and access controls.

Data Privacy

  • Cookies

    Our cookie policy is available within the privacy documents on our legal page.

  • Training

    Nothing you give us is used to train a model.

Access Control

  • Least Privilege

    Each system gets the access its process needs and nothing more, agreed in the written blueprint.

  • Logging

    Security events from the system are logged and kept under your retention rules.

  • Credentials

    Credentials are held in your environment and rotated under your policies.

Change Control

  • Responsible Disclosure

    If you find a security issue in a system we built, tell us and it is ours until it is fixed.

  • Approvals for Change

    No change reaches a system in production without the approval your team has set.

  • Development Lifecycle

    Every system is built against a written blueprint that your engineers review before anything is built.

  • Vulnerability Management

    Dependencies are tracked per system and patched by the engineers who operate it.

Operation

  • Continuity

    Each system can be paused with the work handed back to the people who did it before.

  • Availability

    Systems are deployed on your platforms, so they run where your critical systems already run.

  • Residency

    Where residency requires it, the whole system runs inside your own environment.

Our Engineers

  • Devices

    Our engineers work on managed, encrypted devices.

  • Access

    Engineers reach a client's environment only through the access that client grants and can revoke.

  • Accountability

    The same engineers scope, build and run each system, so responsibility never passes to a team that was not in the room.

Network

  • Boundaries

    Systems sit behind the network boundaries you already operate.

  • Monitoring

    Security events can be sent to the monitoring your security team already uses.

  • Private Connectivity

    Connections to your systems of record use the private routes your team approves.

Our Company

  • Training

    Every engineer is trained on the security and privacy obligations of the work they do.

  • Incident Response

    A security incident has an owner, an escalation path and a person who tells you what happened.

  • Security Review

    We support the security review your team runs before any system goes live.

Report a Vulnerability

Contact the Lyrion security team by email at contact@lyrion.io with the subject line “Responsible Disclosure.”