Trust Center
Last updated: 2026-08-17
Lexabit is a platform for working with transaction data — compliance and financial intelligence for law firms, financial institutions, and other organisations that analyse financial activity. This Trust Center documents our security posture as it is today, including what is still on our roadmap — we would rather give a straight answer than a polished one.
The web application and the API share the same backend and the same access-control path, so everything described here applies to both unless a page states otherwise.
At a glance
- Hosting: EU — DigitalOcean, Amsterdam
- GDPR: the customer is the data controller; Lexabit is the data processor (contracting entity: Lexabit AB (SE), or its Danish entity Lexabit ApS where the customer contracts with it)
- Certifications: see the Compliance Roadmap for current status
- Banking access: via regulated open-banking providers, supervised by their national financial supervisory authorities
- Security contact: security@lexabit.com
Explore the Trust Center
- Security Overview — architecture, access control, and encryption, as they operate today.
- Architecture Overview — components, integrations, infrastructure, and key technical dependencies.
- Security Controls — the full control register, with an honest status for each control.
- Data Protection & GDPR — what data we process, where it lives, and data-subject rights.
- Sub-processors & Service Providers — sub-processors, operational service providers, and banking/data partners.
- Banking & Data Providers — the open-banking and company-data providers we connect to.
- Security FAQ — answers to common questions from IT and security reviewers.
- Compliance Roadmap — current certification status and what's planned.