Security

A geometric lock drawn in thin red lines, with faint rings around it.

This page describes security practices Lynx Labs uses for client work and for this website. It is a summary, not a certification, an audit report, or a guarantee.

Data minimization

Lynx Labs limits client data to what an engagement requires, and keeps it only for that work and for legal duties that apply. This website does not ask for accounts or form submissions. It does not collect personal data beyond messages sent by email.

Encryption

Client data handled by Lynx Labs is encrypted in transit with TLS and encrypted at rest.

Access control

Access to systems that store client data is limited to people who need it for their work. That access requires multi-factor authentication, and it is removed when it is no longer needed.

Vendors

Before a vendor processes client data for Lynx Labs, Lynx Labs puts a business associate agreement in place when the work requires one.

Incidents

If Lynx Labs learns of a security incident affecting client data, it notifies the affected client and cooperates on containment and remediation. Further steps follow the client agreement and applicable law. This page does not promise a specific response time or outcome.

Business associate agreements

Lynx Labs builds with HIPAA requirements in mind. Where a client is a covered entity and the work requires it, Lynx Labs signs a Business Associate Agreement. This page is not a certification of any system.

Report a security issue

Email security@lynxlabs.dev. Describe the issue and how to reproduce it. Do not include patient information or other sensitive client data in the report.