Lexsophos.ai, negotiation intelligence for aviation

Security

Discuss how your contract data would be handled.

Before an evaluation

Review the proposed deployment with your teams.

Each Lexsophos customer environment serves a single organisation and is hosted on Amazon Web Services (AWS). Before evaluating it with company documents, review the proposed deployment and data handling with your legal and information technology teams.

Contact us to discuss where documents are hosted, who can access them, what information is sent for artificial intelligence processing and how it is retained. Include your requirements for export, deletion and security review so those points can be addressed before a pilot.

Email info@lexsophos.ai with your security questionnaire or questions about the proposed evaluation.

AWS's SOC reporting is important supporting assurance, but it is not the same thing as a Lexsophos SOC 2 attestation.

How the AI is used

Where AI processing happens.

AI features use Anthropic Claude models and an Amazon Titan search model through Amazon Bedrock, called from the AWS region agreed for your deployment. Depending on the model, Bedrock may serve requests from other AWS regions within the same geography (for example, within the EU or within the US). That traffic stays on the AWS network and is encrypted in transit. Requests are never routed globally.

Your content is not used to train models.

Under AWS's terms for Amazon Bedrock, your inputs and outputs are not used to train Anthropic, Amazon or any other models, and are not shared with the model providers.

No storage by the AI service.

For the models Lexsophos uses, Amazon Bedrock does not store your prompts or the AI's responses.

The AI cannot act on its own.

The models are given no tools: they cannot browse, call other systems or change documents. AI suggestions become changes only when a person accepts them.

Sign-in and sessions

Two-factor authentication.

Authenticator-app codes, each usable only once, can be required for individual users or for every user in a deployment.

Lockout and rate limits.

After 5 consecutive failed sign-ins, the account locks for 15 minutes. Sign-in and code verification are separately rate-limited.

Passwords are stored only as Argon2 hashes, and sign-in responses don't reveal which email addresses have accounts.

Product controls

How access and records are handled in the product.

Tenant separation is checked at startup.

Each customer environment enforces row-level separation in its Postgres database. In cloud deployments, the application will not start if its database account is allowed to bypass that separation.

Unsafe configuration stops startup.

Cloud deployments with sign-in enabled refuse to start with placeholder secrets, or if configured to call AI from an unapproved region.

Decision history is protected.

Recorded decision events cannot be edited, and can only be deleted when a customer administrator purges the environment's data.

Access follows five built-in roles.

Permissions are assigned through five built-in roles, with support for custom roles where a team needs them.

Audit records are retained.

Audit records are kept for the life of the environment. When a person asks for their data to be erased, their name and email address in those records are replaced with pseudonyms rather than the records being removed. Discuss how this fits your data protection obligations before an evaluation.

Generated content is labeled.

Content produced by artificial intelligence is visibly marked in the workspace and carries a record of how it was produced. Downloaded Word files do not carry this mark.

Data can be exported or erased.

A person's personal data can be exported on request, and an administrator can export your approved clause library. An erasure request pseudonymises the person in the audit history; discuss what else must be removed, such as names inside documents, before an evaluation.

Sign-off can require multiple approvers.

Approval workflows support more than one approver where a team requires it. An authorised case manager can override outstanding approvals.

These points describe the current product. Documentation and compliance details are available on request before an evaluation.