Security & Trust

Evidence should reduce risk, not create more of it.

Lexsentra is being built around least-privilege access, bounded scanning, redacted technical evidence and transparent controls suitable for regulated digital teams.

TLS in transitSSRF protectionsHashed sessionsRedacted network evidence
Scanning safety

Bounded public-surface execution

Public scanning is constrained to reduce abuse and prevent access to internal infrastructure.

  • HTTP/HTTPS only with ports 80/443
  • Private, loopback, link-local and reserved networks blocked
  • Redirect targets revalidated
  • Browser concurrency and free usage rate limited
  • Scan execution time bounded
Evidence handling

Collect less by design

Network evidence is designed to support technical review without unnecessarily retaining sensitive request data.

  • Query strings and fragments removed from stored request URLs
  • Request and response bodies not collected
  • Request and response headers not collected in network manifest
  • Filesystem evidence paths not exposed through scan metadata
  • Evidence responses marked private and no-store
Identity & access

Multi-tenant access model

The platform core supports organizations, workspaces and portfolio-level separation with role-based access.

  • Owner, Admin, Compliance, Analyst, Developer and Viewer roles
  • Session bearer tokens stored only as hashes
  • Passwords stored using salted scrypt hashes
  • Session expiry and revocation supported
  • Workspace-level membership model prepared for enterprise scope
Operational design

Isolated service boundaries

Lexsentra runs as an isolated application stack with dedicated application services and database ownership boundaries.

  • Dedicated API and web service ports
  • Dedicated PostgreSQL application role/database objects
  • Independent scheduled monitoring worker
  • Deterministic regression logic before AI explanation
  • Material-change alerting to reduce noise

Security claims stay evidence-based.

Lexsentra does not currently claim SOC 2, ISO 27001 or other third-party security certification. As the platform matures, this page will evolve into a formal trust center with policies, subprocessors, retention controls, incident procedures and independently verified certifications where appropriate.