Skip to content

1. What this page covers

This page describes the security measures LCAB actually has in the platform. It is not a certificate, not an ISO 27001 statement, and not a promise that nothing can go wrong.

Vulnerabilities can be sent to security@lcab.app. See also /.well-known/security.txt.

2. Organisation isolation

Data in LCAB is tied to your organisation and your access rights. The roles OWNER, ADMIN, MEMBER, and VIEWER control who can view and edit products, materials, documents, and team content.

The API and dashboard use the same access rules. Haddock only gets the context the signed-in session is already allowed to see. Other customers' dashboards are not available.

3. Login and session

Login uses email and password. The platform can require email verification. 2FA (one-time code) can be turned on. Selected organisations can use SAML.

The session sits in a secure cookie. In the signed-in platform a warning is shown after 1 hour without activity, and you are signed out after 2 hours without activity. An active tab can keep the session alive within an upper limit of 12 hours.

4. Transport and headers

LCAB runs over HTTPS. We set security headers, including HSTS, clickjacking protection, content-type nosniff, and a content security policy. Forms and API calls from the browser are protected with a CSRF token (the lcab-csrf cookie).

We use rate limiting and log relevant security events. That is operational control, not monitoring of your product content for marketing.

5. Hosting and sub-processors

The application and database are hosted on Render. Payment is handled by Stripe. Email is sent through Resend. When Haddock or other AI is enabled, messages are processed at Google Gemini to produce an answer.

Card numbers are not stored at LCAB. See /privacy and /dpa for controller and processor roles.

6. Haddock

Haddock is a consultant in the product. It only uses your own context and does not train an LCAB language model. Saved chats stay in your account until you delete them. Temporary chat is not stored in the database.

When the cloud model is used, the message leaves the LCAB server to become an answer. The full text is on /haddock.

7. What we do not claim

We do not claim SOC 2, ISO 27001, or other security certifications unless they are documented separately. We do not claim that data never leaves our servers. We do not claim 100 percent security.

Further company information: www.windfeldjensen.com/data-and-security

Questions about data security can be sent to info@windfeldjensen.com

Windfeld Jensen Co. · CVR 46591054 · 23 97 94 91
Lyngbyvej 83A, 2100 København Ø