Security
Your contracts stay in Europe
Every system that touches your contract text runs inside the EEA, operated by European companies. This page lists them by name, and sets out what the GDPR requires of us as your processor. The binding version is the Data Processing Addendum — if anything here and the DPA disagree, the DPA wins.
Where your data lives
The platform runs on Clever Cloud in France. Contract files are replicated to OVHcloud in Germany for disaster recovery, stored there as sealed ciphertext. Both are European companies operating European infrastructure, which is what removes US CLOUD Act exposure — not a contractual promise about it. EU data residency here means the infrastructure itself, not a region setting on somebody else’s cloud.
Every sub-processor, named
These are the essential sub-processors. Essential means the platform does not work without them, so there is no opt-out. All processing happens within the EEA.
| What it does | Company | Location |
|---|---|---|
| Hosting, database, object storage | Clever Cloud | France |
| Encrypted replication and backup | OVHcloud | Germany |
| Transactional email and notifications | Sweego | France / Netherlands |
| Logging, tracing, error monitoring | Better Stack | Czech Republic |
| Default AI model provider | Mistral AI | France |
These are optional. They process data only if you turn them on.
| What it does | Company | Location |
|---|---|---|
| Electronic signature | Scrive | Europe |
| Slack integration, connected by you over OAuth | Slack | Per your Slack workspace |
| Website analytics — this site only, never contract data | GetResponse | Poland |
The current list, with the full description of what each one processes, is Sub-Appendix B of the DPA. We tell you before a sub-processor is added or replaced, and you can object.
The model layer
Contract text reaches an AI model because reading contract language is what the model is for. What happens to it after that is bounded.
- Your contract text is not used to train models. Lexnus does not do it, and does not permit its AI sub-processors to use your data to train or improve general-purpose or provider-owned models.
- The model only sees what the task needs. AI sub-processors are given personal data only to the extent required to provide the functionality you asked for.
- The model does not decide anything. It reads and extracts. Your published playbook returns the verdict. A rule passes or fails deterministically — the model is not consulted on the outcome.
- If you connect your own AI tool, it is yours. An external AI service you connect with your own credentials or API key is not a Lexnus sub-processor. You control it, under your own agreement with that provider, and our no-training commitment does not extend to it.
Access and authentication
| Authentication | OAuth 2.1 authorisation code flow, or a personal access token issued in Lexnus |
| Scopes | lexnous:read and lexnous:write, enforced on every tool call, for personal access tokens and OAuth alike. An OAuth token carries the scopes the user approved at consent, and the user's Lexnus role still applies within them. |
| Access token lifetime | 15 minutes |
| Refresh token lifetime | 7 days |
| Tenant isolation | A token reaches only the accounts it was granted: one for a personal access token, the ones the user approved at consent for OAuth. Never another customer's data. |
| Session model | Stateless. Every call is authenticated independently, so there is no server-side session to hijack. |
| Document download links | Single use, 15 minutes |
| Original-file attach links | Single use, 7 days |
| Rate limit | 5 requests per second sustained per account, burst 20, on the MCP channel |
| Outbound email | Only for e-signature, and only after a server-issued confirmation step |
The MCP reference documents the authentication model in full, including the tool-level scope for all 27 tools.
The record
Every write is recorded to an append-only log: who did it, which account and workspace, which entity, what operation, and the before-and-after values. Each row is stamped with the channel it arrived through, so a change made by an agent over MCP is distinguishable from one made by a person in the application.
Reads are recorded too: every MCP tool call, read or write, leaves an audit row with the tool's name and whether it succeeded. Tool inputs and outputs are not stored. Every saved edit to a published playbook creates a new version, and every analysis result records the playbook version that produced it. That is what makes a verdict defensible a year later.
What the DPA commits us to
Lexnus processes personal data as your processor under the GDPR (Regulation (EU) 2016/679). You are the controller and we act on your instructions. The obligations below are contract terms in the DPA, not descriptions on a page.
| Data residency | Personal data is processed within the EEA. A transfer outside it requires an adequacy decision or the European Commission’s Standard Contractual Clauses. (DPA 3.6) |
| Encryption | Pseudonymisation and encryption of personal data, alongside the confidentiality, integrity, availability and resilience of the systems that process it. (DPA 3.2a, 3.2b) |
| Recovery | Availability and access restored in a timely manner after a physical or technical incident. (DPA 3.2c) |
| Security testing | Technical and organisational measures tested, assessed and evaluated regularly for effectiveness. (DPA 3.2d) |
| Personal data breach | Written notice to you without undue delay and, where possible, within 24 hours of us becoming aware. (DPA 4.1) |
| Sub-processors | Named in Sub-Appendix B. You are told before one is added or replaced, and you can object. (DPA 9) |
| Audit | Security documentation and questionnaire responses on request. Where that is not enough, a right to audit, through an independent auditor if you use one. (DPA 8) |
| Retention and deletion | On termination you get your data back, and we then delete it. Backups age out under ordinary retention, protected until they do. (DPA 11.3) |
Agreed per contract
The infrastructure and the audit log are the same for every customer. The controls below are not seat-priced — they are negotiated as contract terms.
Questions about security and GDPR
Is our contract text used to train an AI model?
No. Lexnus does not use your data to train models and does not permit its AI sub-processors to use it to train or improve general-purpose or provider-owned models. This is a commitment in the DPA, not a setting.
The one exception is an external AI service you connect yourself with your own credentials. That runs under your agreement with that provider, not ours.
Are we exposed to the US CLOUD Act?
Every essential sub-processor is a European company processing within the EEA: Clever Cloud, OVHcloud, Sweego, Better Stack and Mistral AI. No US-controlled provider processes your contract text.
Website analytics on this marketing site is the only place a standard-contractual-clauses transfer appears, and it never touches contract data.
Is Lexnus GDPR compliant?
Lexnus is the processor and you are the controller. The GDPR obligations that fall on a processor are written into the DPA: EEA processing, encryption and pseudonymisation, breach notice within 24 hours, named sub-processors you can object to, an audit right, and deletion on termination.
Compliance is a property of that arrangement, not a badge we can award ourselves. So read the DPA — this page only tells you where to look.
Is our contract data encrypted?
Contract files replicated to OVHcloud in Germany are stored as sealed ciphertext. Encryption and pseudonymisation of personal data are committed measures in the DPA, section 3.2, along with a process for testing regularly that those measures still work.
For the cipher suites, key management and transport configuration your security team wants on paper, ask us. We would rather answer that in writing than publish a specification here that goes stale.
Can an AI agent connected over MCP reach data it should not?
No. A token reaches only the accounts it was granted, never another customer’s. Personal access tokens and OAuth connections both carry an explicit scope, checked on every tool call, and an OAuth connection carries only what the user approved at consent. Within that, the person’s Lexnus role still applies.
Every write the agent makes lands in the audit log, stamped as arriving over MCP. If an agent changed a rule, you can see it did.
Do you have SOC 2 or ISO 27001 certification?
We provide SOC 2 documentation and support for your security questionnaire. Ask us directly for the current status of any specific certification rather than reading it off this page — we would rather answer precisely than leave a stale claim here.
Do you answer DORA and NIS2 supplier questionnaires?
Yes. Most of what those questionnaires ask a supplier is already here or binding in the DPA: every sub-processor named with its location, processing inside the EEA, a 24-hour breach-notification window, an audit right, and an append-only record of every change. Send it over and we will fill it in.
Who is the contracting entity?
Precisely AB, reg. no. 556963-5286, Nellickevägen 26, 412 63 Gothenburg, Sweden. The full terms are in the Terms of Service and the Privacy Policy.
Send us the questionnaire
If your security team needs something this page does not answer, ask. We would rather go through it with you than publish a claim we have to qualify later.