Trust & Security
Last updated: June 2025
At LexHelps, protecting user data is a core part of our platform architecture. We continuously invest in security, privacy, and infrastructure improvements to ensure user information remains protected.
Security Architecture
LexHelps uses a multi-layer security model designed to protect user accounts, documents, conversations, and AI-generated content.
Security controls include:
- Isolated administrative authentication system
- Multi-Factor Authentication (2FA) for administrators
- JWT-based authentication
- Role separation between users and administrators
- Access control validation for private resources
- Protection against unauthorized file access
- Regular security reviews and infrastructure audits
Data Encryption
LexHelps protects sensitive data both in transit and during backup operations.
Encryption in Transit
All communication between users and the platform is encrypted using HTTPS/TLS.
Backup Encryption
All production backups are encrypted before leaving the production environment using asymmetric encryption.
Encrypted backups include:
- MongoDB databases
- User uploaded files
- Vector databases
- PostgreSQL analytics databases
Private decryption keys are not stored on production systems.
Backup & Disaster Recovery
LexHelps maintains encrypted off-site backups to ensure business continuity and disaster recovery.
Backup coverage includes:
- MongoDB
- Uploaded documents and files
- Vector embeddings
- PostgreSQL services
Features:
- Daily automated backups
- Encrypted backup storage
- Off-site backup infrastructure
- Backup retention policies
- Recovery procedures and documentation
- Recovery testing processes
Data Deletion & User Rights
Users maintain control over their data.
When a user account is deleted, LexHelps removes associated data across connected systems, including:
- User profile information
- Documents and uploads
- Chats and messages
- Document embeddings
- AI-related vector data
- Cached user data
- User relationships and subscriptions
Data deletion processes are continuously reviewed to improve GDPR compliance coverage. For full details on your rights, see our Privacy Policy.
Administrative Security
Administrative access is isolated from the standard user authentication system.
Administrative protection includes:
- Dedicated administrator accounts
- Separate authentication infrastructure
- Multi-Factor Authentication (TOTP)
- Restricted administrative access
- Independent JWT signing keys
- Security monitoring and audit controls
Infrastructure
LexHelps infrastructure is hosted on professionally managed cloud services.
Infrastructure providers currently include:
- Hetzner (Servers & Backup Storage)
- OpenAI (AI Processing)
- Google OAuth (Authentication)
- Apple OAuth (Authentication)
- Telegram (Infrastructure Notifications)
Production backups are stored separately from application servers to reduce operational risk.
Monitoring & Incident Response
LexHelps maintains monitoring and alerting systems for critical infrastructure events.
Monitoring includes:
- Backup execution status
- Recovery operations
- Administrative authentication events
- Infrastructure health monitoring
- Security-related operational alerts
Responsible AI Usage
AI functionality is provided through OpenAI services.
LexHelps reviews AI data flows and storage processes to improve privacy, transparency, and compliance practices.
Contact
Security questions, vulnerability reports, or privacy concerns may be submitted to the LexHelps support team for review.
- Email: support@lexhelps.com
- Help center: Support page