Legal
Security & Trust
Last updated: 25 September 2026
This page describes the security practices that are in place on the Lost Guardians AI platform today. It only lists what is actually built and running — nothing planned is described as current.
Encryption in transit
All traffic between your browser and this website, the client portal and our backend is served over HTTPS, so data is encrypted in transit.
Role-based access control
Every account has one role — Owner, Admin, Staff or Client — and access is enforced by rules in the database itself, not only hidden in the interface. Staff only get the specific permissions an Owner or Admin grants them, and each client can only see their own project, messages, documents and invoices.
Audit logging
Administrative actions that change data (for example account changes, lead updates, payment records and invoices) are written to an audit log that cannot be edited or deleted from the application.
Payment data
Online payments are handled entirely by Lemon Squeezy as Merchant of Record. Card details are entered on Lemon Squeezy's checkout and never reach or are stored by Lost Guardians AI.
Your data rights
Visitors and clients in the EU, EEA and UK can use their GDPR / UK GDPR rights — access, correction, deletion and export — as described in our Privacy Policy.
Healthcare data (PHI)
We do not currently hold a HIPAA compliance certification, and we're not currently set up to execute Business Associate Agreements (BAAs). If your project involves Protected Health Information (PHI), please contact us before sharing any such data — we're happy to have an honest conversation about your specific requirements and whether it's something we can take on.
Contact
Security questions: adnanparvezstudy.345@gmail.com or the Contact page.