Built for enterprise. Certified for compliance.

Lexi was built and tested to meet the security bar banks, telecoms, and insurers require, among the strictest anywhere. That same standard runs for every client we work with, from marketing agencies to tourism boards, and it never slows the work down. Here is exactly how it works, and what our team can send yours.

Why this matters
01

"Fifty people write in your name. Your customer reads one company."

02

"The most-read texts your company sends were never written by marketing."

03

"Companies audit their books. Nobody audits their sentences."

Data protection

Your data stays in the EU, and it's never used to train anyone else's model.

Data residency

All data is processed inside EU infrastructure. Nothing leaves EU jurisdiction.

No data training

Your inputs and outputs are never used to train Lexi's models, or anyone else's.

Access and audit

Granular access control by user and by team, with audit logs available on request.

Data retention

Configurable retention periods, set to match your own internal policies.

Brute-force protection

Rate limiting and brute-force protection built into every API endpoint.

Regulatory compliance

Every generated text is checked against your rules before it ever leaves the system.

Compliance checker

Every generated text is automatically checked against your regulatory rules before it leaves the system. Nothing slips through by accident.

GDPR masker

Personal data (names, national ID numbers, IBANs, addresses) is automatically detected and masked. Critical for support, billing, and CRM communications.

Legal safety

Generated text takes the regulatory parameters you define into account.

Disclaimer management

Mandatory notices and legal disclaimers are applied automatically, wherever your rules require them.

Versioning

Every version of every text is archived, so you can review and prove compliance whenever you need to.

Security standards

Every login, every request, checked.

Two-factor authentication

Mandatory for every user, on every login. No exceptions.

Request-level authorization

Every API request is checked against your RBAC permissions before any data is processed.

Role-based access

Different roles get different levels of access, so people only see what they need to.

Encryption

Data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Architecture & hosting

Multi-tenant, isolated, and hosted entirely in the EU.

EU jurisdiction
Tenants, isolated
Your company
Another client
Another client
Sanitization layer
Ivan Horvat••••• ••••••
HR12 3456 7890•••• •••• ••••
AI layer
Azure OpenAIEU region, Sweden
Google CloudEU region, Belgium
Nothing crosses this boundary

Multi-tenant isolation

Lexi runs as a multi-tenant SaaS platform with full data isolation at the database level. Your data never mixes with anyone else's.

Authentication

JWT-based tokens carry the user ID, company ID, role, and permission scope on every request.

Sanitization layer

Sensitive data passes through a dedicated sanitization layer before it's stored, and before it's sent to the language model. You can also supply your own sanitization model.

Hosting

Google Cloud Platform, EU region (Belgium). Azure OpenAI for the AI layer, also EU region (Sweden).

Independent penetration testing

Tested by Infigo IS in May 2025, with a follow-up test in July 2025.

Certifications

What we can show your security team today.

GDPR Ready Pen-tested by Infigo IS (May & Jul 2025) Mandatory 2FA TLS 1.3 / AES-256 EU AI Act Aligned
For your security & procurement team

Need more for your due diligence?

These are ready to send directly to your security or procurement team, on request.

  • Data Processing Agreement (DPA)
  • Architecture overview
  • Penetration test summary
  • Subprocessor list
  • Security questionnaire responses

Send us your security questionnaire. We'll answer it directly.

No back and forth. Send it over, and our team gets it back to you with everything your procurement or security team needs.

Talk to our team