Compliance Roadmap
Last updated: 2026-08-18
Lexabit is an early-stage platform. We believe security reviews deserve straight answers, so this page states exactly where we are.
Today
- No third-party certifications (ISO 27001, SOC 2) yet.
- No completed external penetration test yet.
- Security controls that ARE live are documented in the Security Overview and labelled In place.
Inherited assurances
- DigitalOcean (infrastructure): independently certified to ISO/IEC 27001 and SOC 2 Type II, and offers a GDPR Data Processing Agreement. See DigitalOcean's trust page for their current certifications.
- Enable Banking (open banking): an authorized open-banking provider, supervised by its national financial supervisory authority.
Planned
- External penetration test.
- A standard Data Processing Agreement (DPA) template.
- A published privacy policy.
- Two-factor authentication (2FA).
- An automated backup regime, alongside a move to a managed database service.
- Private, signed-URL document storage for files currently served by unguessable public URL.
- Scheduled vulnerability scanning of the running application and infrastructure, and a formalized patch-management cadence. (Dependency security auditing and static analysis already run in the development quality gate.)
- Central security monitoring and alerting for suspicious activity (SIEM-style).
- Audit logging of privileged administrative access to production infrastructure.
- Defined and published RPO and RTO, together with the backup regime and recovery testing.
- Movement toward ISO 27001 as our customer base grows.
Planned items describe direction only — they are not part of any current subscription or price. None have committed dates yet; this page will be updated as that changes.
Questions
Contact security@lexabit.com.