Trust & Security

    Last updated: June 2025

    At LexHelps, protecting user data is a core part of our platform architecture. We continuously invest in security, privacy, and infrastructure improvements to ensure user information remains protected.

    Security Architecture

    LexHelps uses a multi-layer security model designed to protect user accounts, documents, conversations, and AI-generated content.

    Security controls include:

    • Isolated administrative authentication system
    • Multi-Factor Authentication (2FA) for administrators
    • JWT-based authentication
    • Role separation between users and administrators
    • Access control validation for private resources
    • Protection against unauthorized file access
    • Regular security reviews and infrastructure audits

    Data Encryption

    LexHelps protects sensitive data both in transit and during backup operations.

    Encryption in Transit

    All communication between users and the platform is encrypted using HTTPS/TLS.

    Backup Encryption

    All production backups are encrypted before leaving the production environment using asymmetric encryption.

    Encrypted backups include:

    • MongoDB databases
    • User uploaded files
    • Vector databases
    • PostgreSQL analytics databases

    Private decryption keys are not stored on production systems.

    Backup & Disaster Recovery

    LexHelps maintains encrypted off-site backups to ensure business continuity and disaster recovery.

    Backup coverage includes:

    • MongoDB
    • Uploaded documents and files
    • Vector embeddings
    • PostgreSQL services

    Features:

    • Daily automated backups
    • Encrypted backup storage
    • Off-site backup infrastructure
    • Backup retention policies
    • Recovery procedures and documentation
    • Recovery testing processes

    Data Deletion & User Rights

    Users maintain control over their data.

    When a user account is deleted, LexHelps removes associated data across connected systems, including:

    • User profile information
    • Documents and uploads
    • Chats and messages
    • Document embeddings
    • AI-related vector data
    • Cached user data
    • User relationships and subscriptions

    Data deletion processes are continuously reviewed to improve GDPR compliance coverage. For full details on your rights, see our Privacy Policy.

    Administrative Security

    Administrative access is isolated from the standard user authentication system.

    Administrative protection includes:

    • Dedicated administrator accounts
    • Separate authentication infrastructure
    • Multi-Factor Authentication (TOTP)
    • Restricted administrative access
    • Independent JWT signing keys
    • Security monitoring and audit controls

    Infrastructure

    LexHelps infrastructure is hosted on professionally managed cloud services.

    Infrastructure providers currently include:

    • Hetzner (Servers & Backup Storage)
    • OpenAI (AI Processing)
    • Google OAuth (Authentication)
    • Apple OAuth (Authentication)
    • Telegram (Infrastructure Notifications)

    Production backups are stored separately from application servers to reduce operational risk.

    Monitoring & Incident Response

    LexHelps maintains monitoring and alerting systems for critical infrastructure events.

    Monitoring includes:

    • Backup execution status
    • Recovery operations
    • Administrative authentication events
    • Infrastructure health monitoring
    • Security-related operational alerts

    Responsible AI Usage

    AI functionality is provided through OpenAI services.

    LexHelps reviews AI data flows and storage processes to improve privacy, transparency, and compliance practices.

    Contact

    Security questions, vulnerability reports, or privacy concerns may be submitted to the LexHelps support team for review.