Legal

Security & Trust

Last updated: 25 September 2026

This page describes the security practices that are in place on the Lost Guardians AI platform today. It only lists what is actually built and running — nothing planned is described as current.

Encryption in transit

All traffic between your browser and this website, the client portal and our backend is served over HTTPS, so data is encrypted in transit.

Role-based access control

Every account has one role — Owner, Admin, Staff or Client — and access is enforced by rules in the database itself, not only hidden in the interface. Staff only get the specific permissions an Owner or Admin grants them, and each client can only see their own project, messages, documents and invoices.

Audit logging

Administrative actions that change data (for example account changes, lead updates, payment records and invoices) are written to an audit log that cannot be edited or deleted from the application.

Payment data

Online payments are handled entirely by Lemon Squeezy as Merchant of Record. Card details are entered on Lemon Squeezy's checkout and never reach or are stored by Lost Guardians AI.

Your data rights

Visitors and clients in the EU, EEA and UK can use their GDPR / UK GDPR rights — access, correction, deletion and export — as described in our Privacy Policy.

Healthcare data (PHI)

We do not currently hold a HIPAA compliance certification, and we're not currently set up to execute Business Associate Agreements (BAAs). If your project involves Protected Health Information (PHI), please contact us before sharing any such data — we're happy to have an honest conversation about your specific requirements and whether it's something we can take on.

Contact

Security questions: adnanparvezstudy.345@gmail.com or the Contact page.