Security

This page describes security practices Lynx Labs uses for client work and for this website. It is a summary, not a certification, an audit report, or a guarantee.
Data minimization
Lynx Labs limits client data to what an engagement requires, and keeps it only for that work and for legal duties that apply. This website does not ask for accounts or form submissions. It does not collect personal data beyond messages sent by email.
Encryption
Client data handled by Lynx Labs is encrypted in transit with TLS and encrypted at rest.
Access control
Access to systems that store client data is limited to people who need it for their work. That access requires multi-factor authentication, and it is removed when it is no longer needed.
Vendors
Before a vendor processes client data for Lynx Labs, Lynx Labs puts a business associate agreement in place when the work requires one.
Incidents
If Lynx Labs learns of a security incident affecting client data, it notifies the affected client and cooperates on containment and remediation. Further steps follow the client agreement and applicable law. This page does not promise a specific response time or outcome.
Business associate agreements
Lynx Labs builds with HIPAA requirements in mind. Where a client is a covered entity and the work requires it, Lynx Labs signs a Business Associate Agreement. This page is not a certification of any system.
Report a security issue
Email security@lynxlabs.dev. Describe the issue and how to reproduce it. Do not include patient information or other sensitive client data in the report.