Defensive by architecture.
Controls are listed only where implemented in the Lapteusé environment — never as marketing vocabulary.
Specific certifications, hosting arrangements and data-residency options are represented only where contractually and technically verified. See the Trust Center below for current status.
Governed across the full lifecycle.
Reasoning, kept inside the boundary.
The model layer never becomes a data-egress path. Context exposure is deliberate, minimal and authorized.
Minimum necessary context is sent to reasoning models — never a full client history by default.
Organization and client authorization is checked before any retrieval.
Raw histories are not indiscriminately sent to models.
Sensitive fields can be excluded by policy.
Model responses are never automatically written as verified facts.
Outputs retain provenance where applicable.
Human review stands in front of consequential decisions.
Status, stated honestly.
Lapteusé does not claim certifications until achieved. The Trust Center states what exists, what is progressing and what is planned — with evidence made available during security review.
| Control | Status | Last Reviewed | Evidence |
|---|---|---|---|
| Identity Verification & MFA | Implemented | Sep 2026 | On request |
| Role / Attribute-Based Access | Implemented | Sep 2026 | On request |
| Client-Level Permissions | Implemented | Sep 2026 | On request |
| Encryption in Transit | Implemented | Aug 2026 | Available under NDA |
| Encryption at Rest | Implemented | Aug 2026 | Available under NDA |
| Key Management | Implemented | Aug 2026 | Available under NDA |
| Audit Logging | Implemented | Sep 2026 | On request |
| Environment Isolation | Implemented | Jul 2026 | Available under NDA |
| Backup Protection & Secure Deletion | Implemented | Jul 2026 | On request |
| Incident Response | Implemented | Sep 2026 | On request |
| SSO / Identity Integration | In Progress | Oct 2026 | Roadmap discussion |
| Independent Penetration Test | In Progress | Oct 2026 | Letter on completion |
| SOC 2 Type II | Planned | — | — |
| Data-Residency Options | Planned | — | — |
| On-Premise Deployment | Not Applicable | — | Private deployment on request |
Status accurately reflects the current environment at the time of review. Independent reports and architecture documentation are shared during the security review process.
Secure the intelligence behind the relationship.
Request a security review with your organization’s requirements.