Enterprise-Grade Security

Absolute discretion.
Zero drama.

Lia operates on private, secure, encrypted infrastructure. Vault-level security isn't a feature, it's a promise.

Compliance & Encryption

Locked tight

SOC 2 Type II Certified

Lia runs on SOC 2 Type II certified infrastructure, independently audited, continuously verified.

AES-256 at rest, TLS 1.2+ in transit

Every credential, every token, every connection, encrypted before it touches storage.

Zero-knowledge token storage

Your Google OAuth tokens are encrypted. Even we can't read your credentials.

AI Threat Defense

4 layers deep

Regex pre-filter

Sub-millisecond scan for known prompt injection patterns. Caught instantly.

Lakera Guard

ML-powered injection detection. Obfuscated attacks and novel patterns blocked before reaching the model.

Output validation

Every outbound email scanned for leaks. If something looks wrong, it doesn't send.

Per-user rate limiting

Hard caps on actions to limit blast radius. Every limit hit is logged.

Infrastructure & Testing

Proven, not promised

Per-user agent isolation

Every user gets their own isolated agent and memory. Your data never crosses into anyone else's.

Railway + Supabase Postgres

Production-grade infrastructure with automated daily backups.

Promptfoo CI

Automated red-teaming on every code push. If an injection gets through, the build fails.

Real data deletion

Run /delete and everything goes. No soft-deletes, no retention windows. Gone means gone.

What we believe

Questions about security?

We're happy to discuss our security practices in detail.

Contact us