Security · Last updated 14 May 2026
How we protect your data.
Your delivery plans, your people's names and your contractor spend live here. Here's what we do with that.
Encrypted
TLS 1.3 in transit, AES-256 at rest.
Isolated by organisation
Every table is row-level-security scoped to your organisation. A buggy query still can’t read another customer’s data.
Sign-in
Email and password, magic link or Google. SSO with your identity provider is available as contracted Enterprise work. Sessions expire when idle.
Audit log
Decisions and key changes are logged with who and when. 90 days on Team, unlimited on Enterprise.
Data location
Hosted in Sydney (ap-southeast-2).
AI and your data
Lighty runs on Anthropic’s commercial API, which doesn’t train on your data. Neither do we.
How we operate
- No routine human access to customer data.
- Every pull request runs type checks, lint and the test suite.
- Daily database backups.
- We notify affected customers within 72 hours of a breach, per GDPR and the NDB scheme.
Report a vulnerability
Email security@lighthouse.delivery. We reply within one business day and triage by severity. We'll credit you publicly if you like. No bug bounty yet.
Procurement and vendor review
We have a CAIQ-Lite questionnaire and a DPA ready, and engineers for vendor-review calls. Email security@lighthouse.delivery or use contact.