Data residency
Everything lives in the UK. Our database runs on Supabase hosted in the UK, and our serverless functions run in Vercel's EU West 2 region (London). Your data doesn't leave UK infrastructure.
Isolation and access control
We use Supabase's Row Level Security across the database. Access is enforced at the database layer, not just the application layer, so even if something went wrong at the application level, the data access rules still hold. Each organisation's data is isolated from every other.
Encryption
All data is encrypted in transit via TLS and at rest using AES-256. Passwords are salted and hashed rather than stored in any readable form, and the secrets the platform needs server-side are held in an encrypted secret store rather than in ordinary database columns.
Authentication
Authentication is handled through Supabase, supporting email and password or magic link sign-in. Multi-factor authentication with an authenticator app is available and can be enabled per user. Team owners and admins can see which of their members have turned it on.
Backups and recovery
We run regular backups with point-in-time recovery, which means we can restore the database to any specific moment rather than just the last scheduled snapshot.
Infrastructure security
Our infrastructure runs on Supabase, which holds SOC 2, HIPAA, and ISO 27001 certifications. Supabase works with external security experts to conduct regular penetration testing. DDoS protection runs at the CDN level through Cloudflare, with additional brute force protection and rate limiting applied on top.
What data AI Sentri holds
AI Sentri stores governance and operational data about your AI estate: system inventory records, ownership and approval trails, policy documents, risk register entries, ROI figures, governance posture scores, and the evidence your organisation generates through its review cycles.
That does include personal data, and we would rather be plain about it than reassuring. We hold the name and email address of everyone with an account, and the names your team records against systems, policies, risks and KPIs as owners, sponsors and approvers. It is workplace contact and accountability information, so a subject access request would reach it, and we will help you answer one.
What we do not hold is your customers' data, or special category data such as health or biometrics. The product is not built to store it and it should not be put there.
Who else touches your data
These are the only third parties involved in running the product. We do not sell data, and we do not share it with anyone not on this list.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and serverless functions | UK (London) |
| Vercel | Application hosting and delivery | EU West (London) |
| Resend | Transactional email, such as invitations and notifications | EU / US |
| Google Analytics | Traffic measurement on the public marketing site only, never inside the product | EU / US |
No payment card details are taken through the platform at all. Plans are invoiced directly, so there is no card data to store or process.
Who can see what, and getting your data out
- •Roles. Owners and admins manage members and settings; everyone else works within the organisation without those rights. Each organisation is a separate boundary in the database.
- •Joining is by invitation. An invitation is bound to the address it was sent to and to the role it was issued with; neither can be altered by the person accepting it.
- •Deletions are recorded. Removing records writes an audit entry, and that record survives the deletion of the thing it describes.
- •Leaving. Deleting an organisation removes its data. You can export your estate, roadmap and action plan to PDF at any point before that, and we will help you get a fuller export if you ask.
How we test our own security
We ask our customers to evidence their AI governance, so we hold ourselves to the same standard. This work is continuous rather than an annual event.
- •Automated static analysis. Our code is scanned continuously for security defects, with findings raised against the specific line that caused them.
- •In-depth reviews. We run periodic reviews across the whole codebase, covering tenant isolation, access control, authentication and the public surfaces. Candidate findings are independently checked before they are accepted, so what we act on is verified rather than assumed.
- •Fixes are proven, not presumed. Anything touching data access is reproduced first, fixed, then re-tested against a staging copy of the production database before it is promoted. We confirm the legitimate paths still work, not only that the problem is closed.
- •The database is the boundary. Access rules live in the database rather than only in the application, and they are re-tested whenever they change.
We do not publish the detail of individual findings. Describing an open weakness in public helps the wrong people first. If you are evaluating us and need more than this page offers, ask and we will go through specifics under NDA.
Reporting a vulnerability
If you believe you have found a security issue, email sales@lashandigital.co.uk with enough detail to reproduce it. We will acknowledge your report, keep you updated while we work on it, and credit you if you would like us to. We will not pursue legal action over good-faith research that respects other customers' data and does not degrade the service for them.
AI Sentri certifications
We don't currently hold our own SOC 2 or ISO 27001 certification. The platform is built on infrastructure that carries those certifications, and we've designed our own practices to align with those standards. Formal certification at the application level is on the roadmap. If you're in a procurement process that requires documentation, get in touch and we'll tell you what we can provide.
Questions
If you're doing a security review or want to understand how your data is handled, reach out and we'll give you a straight answer.