Single sign-on (SAML / OIDC)
Access through your own identity provider and policies.
Lexa fits environments where controls are part of the contract. The essentials ship from day one, and we say plainly what's certified and what's roadmap.
Part of the platform, not add-ons you negotiate later.
Access through your own identity provider and policies.
Hold your own encryption keys. Your data stays yours.
AES-256 at rest, TLS 1.3 in transit. No exceptions.
An append-only record of every action. Defensible when it counts.
Your data stays in the region you choose.
Each customer's data is separated by design. Never co-mingled.
We won't claim certifications we don't hold. These are targets we're working toward.
In progress · Controls being put in place
In progress · Target set, timeline shared on request
Certifications we're earning, not claiming
SOC 2 Type II and ISO 27001 are in progress, not yet certified. Until they land, we share controls, evidence, and pen-test summaries, and complete your security questionnaire on request.
Bring your security review and your hardest questions. We answer with evidence.