SECURITY AND DATA

Security and data handling

Two different things are usually mixed together under this heading: what a website does, and what a workflow does. They are separated below. The second half is honest about what is decided with each client rather than promised to everybody in advance. A promise made to everybody in advance is usually the one that turns out to be conditional.

Last reviewed 5 September 2026.

1This site

  1. 1.1This site sets no cookies. It runs no analytics, no tag manager and no tracking pixel.
  2. 1.2It loads nothing from a third party, its fonts included, which are served from this domain. A content security policy restricts what the pages may load, and there is no third party in it to restrict. There is no form on it, so nothing is submitted anywhere.
  3. 1.3If you write to the address on the contact page, your address is used to reply to you and for nothing else. It is not added to a list, because there is no list.
  4. 1.4Server logs are kept by the hosting provider in the ordinary course. I do not build a profile from them and I do not join them to anything.

2Where a workflow runs

  1. 2.1Workflows are designed to run inside your own environment, or in a region you choose. That is a design constraint written into the brief before anything is built.
  2. 2.2It is one of the first questions on the scoping call, because it changes what is possible afterwards.
  3. 2.3Where a model is called, which provider and which region are named in the design brief, together with the account settings that apply.

3Sources

  1. 3.1The sources an agent may read are fixed in advance, by name, and enforced in configuration rather than in an instruction.
  2. 3.2Every run logs what it actually read.
  3. 3.3An agent that reaches outside its list is a failed run, not a feature.

4Logs and retention

  1. 4.1What is logged, who may read it, how long it is kept and how it is deleted are decided with you and written into the design brief.
  2. 4.2The default I argue for is metadata and the review trail rather than full prompts, with a stated retention period and a deletion rule.
  3. 4.3The line “every record kept” on this site means kept for the period agreed with you, in your systems. It is not a promise to keep anything for ever, and a retention rule is part of good handling rather than a contradiction of it.

5Model training

  1. 5.1The design brief names the provider terms and the account settings that keep your content out of model training. The pilot does not start until they are in place and someone on your side has read them.
  2. 5.2I write the requirement and check the setting. The contractual promise is the provider’s to make to you, and it should be read as such.

6Subprocessors

  1. 6.1Named per engagement, in writing, before any data moves.
  2. 6.2There is no global subprocessor list on this page, because the stack differs by client. A list that is not true of your engagement would be worse than no list.
  3. 6.3The foundation model provider is treated as a subprocessor and named like any other.

7Data protection responsibilities

  1. 7.1Your organisation is the data controller and makes the compliance call. LEXSAS designs to that decision, records it, and says plainly where a design would make it harder to defend.
  2. 7.2Lawful basis, minimisation, retention, logging and any cross-border transfer are settled in the design brief before a pilot starts. The transfer mechanism is named, and the notification duty and its period are allocated.
  3. 7.3Under KVKK and under GDPR the questions are different in detail and the discipline is the same: decide it in writing, before the run.

8What does not go into a system whose terms have not been read for it

  1. 8.1Special-category personal data. Evidence and enforcement file content. Negotiation strategy. Anything covered by professional secrecy.
  2. 8.2This is the line the Union of Turkish Bar Associations drew for lawyers in its advisory guide of 28 August 2026. It is a sensible line for an in-house team as well.

9Incidents

  1. 9.1The playbook exists before the incident. It says preserve first, meaning capture the prompt, the output, the model version and the logs before any rollback, session clearing or key rotation, because those three moves destroy the evidence. Then contain.
  2. 9.2It names who may switch a workflow off and who tells the business.
  3. 9.3Notification duties sit with you as controller. The record is what makes a notification possible inside the period the law allows.

10What I do not claim

  1. 10.1LEXSAS holds no security certification and does not imply one. It is a venture founded in 2026 and led by one founder.
  2. 10.2Where your procurement requires a certification, the honest answer is that I do not have it, and the design should place the certified components with the providers who do.
  3. 10.3To report a vulnerability in this site, see security.txt.

The clauses behind this page are sections 9 and 10 of the operating standard. The terms used here are defined in the glossary. If your procurement has a question this page does not answer, Get in touch