Security and data handling
Written for the person who has to fill in the questionnaire. No certifications yet; here is exactly what we do.
Isolation
Each customer’s files are stored in a dedicated private storage bucket, provisioned at signup. Each customer’s records are kept in a shared database where access is enforced per customer by the database itself: every request reads and writes under a role that can see only that customer’s rows. The analysis runs in a shared pool under one analysis identity that reads and writes only the storage path handed to it per run, holds no database credential, and never serves a request from you or anyone else.
Retention and deletion
Uploaded files are purged 30 days after the report is generated unless you choose to keep them; reports, findings and research threads stay until you delete the study. You can delete a study, or the workspace’s entire data set, from Settings. On cancellation we delete your file storage immediately and your database records within seven days. Residual copies in our providers’ encrypted infrastructure backups are purged within 30 days. Billing records are retained as required by law.
AI provider
Content sent to our AI provider is not used for training and is not retained by default; where the provider requires it, retention is 30 days, and content flagged by the provider’s safety systems may be retained for up to two years. Analysis is performed on the provider’s infrastructure; data at rest with the provider is in United States. Your storage and database are in Singapore (asia-southeast1) (EU customers: Frankfurt), chosen at signup and immutable after that.
Who can see your files
One person at Lynx, and every access is logged in an append-only access log that you can read yourself in Settings, including our own. Debugging a workspace is an explicit, time-boxed, logged impersonation. There is no unlogged administrative read path.
What the analysis is, and is not
Every figure is read from a page and checked by code, and more than 200 models built in house compute the indicators from those figures; models read, judge and write prose, and every numeric claim in the report is verified against the figures before publication. The output is a screening analysis of accounting risk on the filings you upload. It is not investment, credit, audit or legal advice, and must not be used to make a decision about a natural person.
Subprocessors
A dated register, with an email notice before any change. What each kind of service holds:
Services we use
We keep the list of services we use deliberately short. Each holds only what is listed. The providers are named in the sub-processor register on the DPA page.
Categories
• Hosting — the application, its deploys and operational logs.
• Databases — customer records, with access enforced per customer organisation by the database itself.
• Sign-in — sign-in, organisation and invitation records, authentication emails.
• Compute and storage — analysis jobs, per-organisation file storage buckets, job scheduling, secrets.
• Payment processing — card details are handled by the payment processor and never stored by us.
• Email delivery — transactional email (for example, report-ready notifications).
• AI inference services — your documents and data extracted from them are processed by AI models to produce the analysis.
What leaves your bucket
Uploaded filings and their page images stay in your organisation's private storage bucket and are read by the analysis jobs and the inference services above. They are not used to train models and are not shared with other customers.
Contracts
Standard terms with a data-processing addendum and an AI addendum, governed by Singapore law. EEA standard contractual clauses and the UK addendum are incorporated by reference.
Incidents and backups
Daily encrypted backups of your database with a 7-day recovery window (not point-in-time). Internal breach notification within 48 hours, customer notification within the statutory windows.