Security and Data Protection
How Lacewing Technologies LLC handles client data, credentials and AI model providers. Written plainly, because security pages that hide behind jargon are not much use to anyone.
In plain English
- Only the content needed to produce a result is sent to a model provider, and where a build allows it we strip or mask identifiers before content leaves your environment.
- We rely on a small set of established sub-processors for hosting, email, payments, error monitoring, analytics and AI model APIs.
- Secrets live in environment configuration and secret managers, never in source control. Dependencies are pinned and updated rather than left vulnerable.
- We never see or store raw card numbers. Payments are processed by established providers that handle card data.
This summary is for orientation only and is not part of the policy. The full text below is what applies.
AI model providers
Our products and client builds call large language models from commercial providers. Two things matter about that, and we are explicit about both:
- What is sent. Only the content needed to produce a result is sent to a model provider. Where a build allows it, we strip or mask identifiers before content leaves your environment.
- What providers may do with it. We use provider tiers whose terms exclude customer content from model training. Where a client requires a specific provider, region or self-hosted model instead, we build to that requirement.
Sub-processors
We rely on a small set of established providers to operate: cloud hosting and storage, email delivery, payment processing, error monitoring and analytics, and AI model APIs. Each is engaged under terms that require them to protect the data they process. A current list for a specific engagement is available to that client on request.
Secure development
- Secrets are kept in environment configuration and secret managers, never committed to source control.
- Dependencies are pinned and updated; known-vulnerable packages are replaced rather than ignored.
- Input from users and from models is validated before it reaches a database, a shell or another system.
- Deployments run through repeatable pipelines, so what is reviewed is what ships.
- Logging captures what is needed to debug and audit, without storing credentials or unnecessary personal data.
Payments
We never see or store raw card numbers. Product subscriptions are processed by established payment providers that handle card data on their own PCI-compliant infrastructure. Client invoices are settled by bank transfer.
Confidentiality
Every engagement carries a mutual confidentiality obligation, and we sign client NDAs on request before any material is shared. Project details are never used as public examples without written permission.
Incidents
If we become aware of a security incident affecting client or user data, we investigate immediately, contain it, and notify the people affected along with any regulator the law requires, without waiting for the investigation to be finished.
Business continuity
Code lives in version control with off-site backups, and infrastructure is defined as configuration so an environment can be rebuilt rather than nursed. Because client work is deployed into client-owned accounts, delivery does not depend on our infrastructure staying up.
Reporting a vulnerability
If you find a security issue in any Lacewing Technologies product or in something we built, email dipak@lacewingtechllc.com with the details. We acknowledge reports within one business day and will keep you updated until it is resolved. Please give us a reasonable window to fix an issue before disclosing it publicly.
Questions about this policy?
Write to dipak@lacewingtechllc.com or call +91 91373 36125, Monday to Friday, 10:00 to 19:00 IST. Postal enquiries to Lacewing Technologies LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States.
