Security
Trust is the product. Below is how we approach security and where we are in formalizing it. We state only what is true today and mark what is in progress.
Data handling
- Encryption in transit (TLS) for all API and site traffic.
- Encryption at rest for stored data.
- Least-privilege access to production systems, with audit logging.
- Query content is processed to return resolved results and is not used to train models; how long we keep it is set out in the Privacy Policy.
Resilience against hostile input
Because the web is adversarial, your agent only ever receives resolved facts and the record behind each one. Every value carries the document it came from, so outputs can be checked rather than taken on faith.
Compliance
- Privacy: see the Privacy Policy and Data Processing terms for B2B.
- SOC 2 Type II: planned, not yet certified. We will publish status when an audit is underway.
- A Trust Center with reports, DPA, and sub-processors will be available for enterprise review; in progress.
We will not claim a certification we do not hold. This page is updated as that posture matures.
Reporting a vulnerability
Email support@lokaah.ai with details and reproduction steps. We acknowledge reports promptly and work in good faith with researchers. Please do not publicly disclose before we have addressed the issue.