Security & Data Privacy
Lennexus is built for finance teams that need to trust their system of record. Here is how we protect your data.
Encryption at rest and in transit
All data stored in Lennexus is encrypted using AES-256. Every connection — browser to server, server to database, server to object storage — is protected by TLS 1.2 or higher. There is no unencrypted path to your data.
Role-based access control
Three purpose-built roles — Controller (full access), ESG Manager (create and edit credits and retirements), and Auditor (read-only) — enforce the principle of least privilege. Role checks are enforced server-side on every API request. UI-level restrictions cannot be bypassed.
Immutable audit trail
Every create, edit, and retirement is logged with the user identity, timestamp, IP address, and before/after field values. The audit log cannot be modified or deleted, even by administrators.
Backups and disaster recovery
The database is backed up daily with point-in-time recovery. Backups are retained for 30 days. Document files are replicated across multiple availability zones. Recovery time objective (RTO) is under 4 hours.
Authentication
Lennexus uses OAuth 2.0 for authentication. Session tokens are short-lived and signed with a server-side secret. There is no client-side trust — permissions cannot be bypassed through UI manipulation.
Compliance posture
Lennexus is built on SOC 2-aligned controls. We are completing our formal SOC 2 Type II audit. Enterprise customers can request our security documentation and current compliance posture by emailing enterprise@lennexus.com.
Questions? Contact security@lennexus.com. We respond within 48 hours.