Skip to main content

Compliance Roadmap

Last updated: 2026-08-18

Lexabit is an early-stage platform. We believe security reviews deserve straight answers, so this page states exactly where we are.

Today

  • No third-party certifications (ISO 27001, SOC 2) yet.
  • No completed external penetration test yet.
  • Security controls that ARE live are documented in the Security Overview and labelled In place.

Inherited assurances

  • DigitalOcean (infrastructure): independently certified to ISO/IEC 27001 and SOC 2 Type II, and offers a GDPR Data Processing Agreement. See DigitalOcean's trust page for their current certifications.
  • Enable Banking (open banking): an authorized open-banking provider, supervised by its national financial supervisory authority.

Planned

  • External penetration test.
  • A standard Data Processing Agreement (DPA) template.
  • A published privacy policy.
  • Two-factor authentication (2FA).
  • An automated backup regime, alongside a move to a managed database service.
  • Private, signed-URL document storage for files currently served by unguessable public URL.
  • Scheduled vulnerability scanning of the running application and infrastructure, and a formalized patch-management cadence. (Dependency security auditing and static analysis already run in the development quality gate.)
  • Central security monitoring and alerting for suspicious activity (SIEM-style).
  • Audit logging of privileged administrative access to production infrastructure.
  • Defined and published RPO and RTO, together with the backup regime and recovery testing.
  • Movement toward ISO 27001 as our customer base grows.

Planned items describe direction only — they are not part of any current subscription or price. None have committed dates yet; this page will be updated as that changes.

Questions

Contact security@lexabit.com.