Legal
Security at Lisan
Built for customers whose security teams ask hard questions.
Lisan serves governments and regulated enterprises, so this page says what we do today, what we can show, and what is still on the roadmap. Every statement on it is kept in a claims ledger and checked against our code and server configuration before it is published.
Deployment options are the security model
The strongest control we offer is architectural: you decide where data lives. Managed cloud for speed, self-hosted servers for control, on-premises deployments for sovereignty, and local-only modes where products support them. Data that never leaves your network never needs a promise from us.
Platform practices
- Encryption in transit for all services: every public host serves HTTPS with certificates that renew automatically.
- One database, operated by us: the managed cloud runs on a single-tenant Postgres server in one region (United States, us-east-1), not on a shared database provider. Workspace isolation is enforced in the database with row-level security policies, switched on for 1,302 of its 1,311 tables as of 4 October 2026, with role-based permissions in every product.
- Secrets live encrypted in the database vault and are read by name; the tokens of connected accounts are encrypted before they are stored.
- Nightly backups: a database dump verified before upload, the cluster roles, user files and the server configuration go to private, versioned object storage every night, and a restore rehearsal loads a dump into a throwaway database to prove it restores.
- Sign-in is email and password with an emailed confirmation code; the desktop apps sign in with a one-time email code. Mail and calendar connections use the provider's own sign-in screen, so Lisan never holds a mailbox password. Authenticator-app two-factor sign-in ships in SignX and is on the roadmap for the rest of the platform.
- Scoped, revocable API keys with usage logging where APIs exist, and audit logs in the products that keep one: the CRM, documents, signatures and the admin console.
- Code-signed desktop installers, served and updated exclusively from Lisan's own release infrastructure at updates.lisan.org.
- Private-by-default sharing: nothing is public unless you make it so, and share links can carry expiry.
- Monitoring: off-server uptime probes every 30 minutes and database-side alerts every five minutes (a missed backup, a failed deploy, a failing job) email the engineer on call. A public status page is on the roadmap.
What we do not claim yet
No SOC 2 report, no ISO 27001 certificate and no third-party penetration test report exist today, and none is implied anywhere on this site. Single sign-on through your identity provider (SAML or OIDC), customer-managed encryption keys and end-to-end encryption are not offered; the first is on the roadmap, undated. Disk-level encryption at rest for the managed cloud's data volumes is on the roadmap to verify and publish here, so we do not state it until we can show it. If a questionnaire needs a specific attestation, ask and we will answer with what is true.
Responsible disclosure
If you believe you have found a vulnerability in any Lisan product, email support@lisan.com with details. We take reports seriously and respond quickly.
Questions
Security reviews are a normal part of how our customers buy. For questionnaires and deployment-specific documentation, talk to us.