Security · Last updated 14 May 2026

How we protect your data.

Your delivery plans, your people's names and your contractor spend live here. Here's what we do with that.

Encrypted

TLS 1.3 in transit, AES-256 at rest.

Isolated by organisation

Every table is row-level-security scoped to your organisation. A buggy query still can’t read another customer’s data.

Sign-in

Email and password, magic link or Google. SSO with your identity provider is available as contracted Enterprise work. Sessions expire when idle.

Audit log

Decisions and key changes are logged with who and when. 90 days on Team, unlimited on Enterprise.

Data location

Hosted in Sydney (ap-southeast-2).

AI and your data

Lighty runs on Anthropic’s commercial API, which doesn’t train on your data. Neither do we.

How we operate

  • No routine human access to customer data.
  • Every pull request runs type checks, lint and the test suite.
  • Daily database backups.
  • We notify affected customers within 72 hours of a breach, per GDPR and the NDB scheme.

Report a vulnerability

Email security@lighthouse.delivery. We reply within one business day and triage by severity. We'll credit you publicly if you like. No bug bounty yet.

Procurement and vendor review

We have a CAIQ-Lite questionnaire and a DPA ready, and engineers for vendor-review calls. Email security@lighthouse.delivery or use contact.