Localign
Security overview

How we protect your data

A high-level summary of the security posture behind Localign: encryption, access, vulnerability management and incident response. The detailed control inventories live under Controls; this is the summary you can share with a CISO or DPO.

Questions about your assessment?trust@localign.com
All systems operationalService status
HostingEU (Netherlands, France)
ModelsOpen source, EU-hosted
Training on customer dataContractually prohibited
Escalation to an external modelConsent per question
01

Encryption

Transport + secrets

TLS 1.2 or higher for everything in transit, including the WebSocket that streams answers to your browser. Data at rest is protected by the underlying managed database and object-storage layers. For especially sensitive application secrets such as stored mailbox credentials and OAuth tokens, Localign adds application-level AES-GCM encryption before they are written to the database. When files need to be downloaded, the backend issues time-limited presigned URLs instead of exposing a permanent public path, and production-like deployments mount secrets as files rather than plaintext application variables.

In transit
TLS 1.2+
Sensitive secrets
AES-GCM in app layer
02

Access control

Least privilege

Internal access follows least-privilege and need-to-know principles. Engineers do not access customer data in the course of normal operations; access for support purposes is opt-in by you per ticket and is logged. On the customer side, organisation administrators control who can use Localign, who can manage assistants, and which providers are reachable in Mode B. Multi-factor login is supported for end users. User sessions use short-lived access JWTs in the browser while the refresh token stays in an HttpOnly cookie, and the client refreshes before protected HTTP calls and WebSocket reconnects. Document and assistant access is enforced server-side against conversation, personal, organisation, assistant and project scope, and organisations can disable Google and Microsoft social login.

Support access
Per ticket, opened by you
Session model
Short-lived JWT + HttpOnly refresh
03

Auditability

Traceability

Every conversation has a stable trace identifier. Trial conversations can be reviewed from the organisation side, while normal customer conversations are not exposed there by default. Subprocessor changes are published on the Sub-processors page and notified to the contact in your DPA. In the product itself, each answer can be inspected for models used, document and web sources, and the PII timeline that records detection, consent requested, consent granted or denied, and any external model actually used.

Traceable
Stable trace id per conversation
In product
Models, sources and PII timeline
04

Vulnerability management

Assurance

Static analysis runs in SonarQube and findings are tracked through the normal engineering workflow. An external penetration test is performed annually, scoped to the customer-facing trust boundary. Renovate keeps dependencies current and a documented exception process governs anything that cannot be auto-upgraded. Dependency updates are automated across the frontend and backend repositories, and the frontend package manager is configured to block trust-policy downgrades and exotic dependencies.

External pentest
Annual
Engineering controls
SonarQube + Renovate
05

Incident response

Detection & notification

We follow a documented incident-response procedure with named roles, escalation paths and rehearsed drills. Customer-affecting incidents are notified within the windows set by GDPR article 33 (personal data) and DORA (where applicable to financial-services customers). The Service status page describes what we publish during an incident; the Updates page lists structural changes that came out of past incidents. The AI engine also exposes Prometheus metrics for latency, time-to-first-token and error rates, sends heartbeat events during long streams, and forwards ERROR-level logs to Mattermost for operational alerting.

Personal-data breach
GDPR art. 33 timing
Financial customers
DORA windows also apply

Another question about your assessment?

We usually answer questions from CISOs, DPOs and procurement teams within two working days.