Security
Security and data handling
Laylight asks to read the systems your organisation runs on. This page states what we access, how it is protected, and, just as importantly, what we do not yet claim.
What Laylight accesses
Laylight reads only the sources you explicitly connect and scope. Connecting an integration does not grant access to an entire workspace by default: you choose the channels, folders, spaces, repositories, mailboxes, calendars or tables Laylight may index, and you can narrow or revoke that scope at any time.
Access is read-only for retrieval. Laylight does not post, send, modify or delete content in your connected systems as part of answering a question.
Authorisation and credentials
- Connections are authorised through each provider’s own OAuth flow. Laylight never asks for and never stores your passwords for a connected system.
- Access tokens are stored encrypted and are scoped to the permissions granted at connection time.
- Revoking a connection, in Laylight or in the upstream provider, stops further access immediately.
- Authentication into Laylight itself is handled by a third-party identity provider (WorkOS).
Data protection
- All traffic to and from Laylight is encrypted in transit over TLS.
- Indexed content and credentials are encrypted at rest.
- Data is segregated by organisation. Queries are scoped to the requesting organisation, and content indexed for one customer is never used to answer another customer’s question.
- Your content is not used to train foundation models, and is not shared with third parties for that purpose.
Retention and deletion
Disconnecting an integration removes the content Laylight indexed from it. On request to [email protected] we will delete your organisation’s indexed content and account data.
Subprocessors
Laylight relies on third-party infrastructure for hosting, identity and model inference. We will publish and maintain a current subprocessor list here before general availability, and will notify customers of material changes to it.
What we do not claim yet
Laylight is pre-launch. To be explicit, rather than leaving it to inference:
- We do not hold a SOC 2, ISO 27001 or equivalent third-party audit at this time.
- We have not completed an independent penetration test.
- We do not currently offer a self-hosted or customer-managed-key deployment.
- We do not yet publish uptime commitments or a formal SLA.
We would rather say this plainly than let an absent page imply otherwise. If a compliance requirement is a condition of your evaluation, tell us at [email protected] and we will tell you honestly where it sits on our roadmap.
Reporting a vulnerability
Email [email protected] with the subject line “Security”. We will acknowledge within three business days. Please give us reasonable time to remediate before public disclosure, and do not access data belonging to anyone other than yourself while testing.
Related: how the product works and what each integration reads.
