Built for enterprise. Certified for compliance.
Lexi was built and tested to meet the security bar banks, telecoms, and insurers require, among the strictest anywhere. That same standard runs for every client we work with, from marketing agencies to tourism boards, and it never slows the work down. Here is exactly how it works, and what our team can send yours.
"Fifty people write in your name. Your customer reads one company."
"The most-read texts your company sends were never written by marketing."
"Companies audit their books. Nobody audits their sentences."
Your data stays in the EU, and it's never used to train anyone else's model.
Data residency
All data is processed inside EU infrastructure. Nothing leaves EU jurisdiction.
No data training
Your inputs and outputs are never used to train Lexi's models, or anyone else's.
Access and audit
Granular access control by user and by team, with audit logs available on request.
Data retention
Configurable retention periods, set to match your own internal policies.
Brute-force protection
Rate limiting and brute-force protection built into every API endpoint.
Every generated text is checked against your rules before it ever leaves the system.
Compliance checker
Every generated text is automatically checked against your regulatory rules before it leaves the system. Nothing slips through by accident.
GDPR masker
Personal data (names, national ID numbers, IBANs, addresses) is automatically detected and masked. Critical for support, billing, and CRM communications.
Legal safety
Generated text takes the regulatory parameters you define into account.
Disclaimer management
Mandatory notices and legal disclaimers are applied automatically, wherever your rules require them.
Versioning
Every version of every text is archived, so you can review and prove compliance whenever you need to.
Every login, every request, checked.
Two-factor authentication
Mandatory for every user, on every login. No exceptions.
Request-level authorization
Every API request is checked against your RBAC permissions before any data is processed.
Role-based access
Different roles get different levels of access, so people only see what they need to.
Encryption
Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
Multi-tenant, isolated, and hosted entirely in the EU.
Multi-tenant isolation
Lexi runs as a multi-tenant SaaS platform with full data isolation at the database level. Your data never mixes with anyone else's.
Authentication
JWT-based tokens carry the user ID, company ID, role, and permission scope on every request.
Sanitization layer
Sensitive data passes through a dedicated sanitization layer before it's stored, and before it's sent to the language model. You can also supply your own sanitization model.
Hosting
Google Cloud Platform, EU region (Belgium). Azure OpenAI for the AI layer, also EU region (Sweden).
Independent penetration testing
Tested by Infigo IS in May 2025, with a follow-up test in July 2025.
What we can show your security team today.
Need more for your due diligence?
These are ready to send directly to your security or procurement team, on request.
- Data Processing Agreement (DPA)
- Architecture overview
- Penetration test summary
- Subprocessor list
- Security questionnaire responses
Send us your security questionnaire. We'll answer it directly.
No back and forth. Send it over, and our team gets it back to you with everything your procurement or security team needs.
Talk to our team
