Four things you are actually asking about. Answered plainly.
Who can get in, what the AI is allowed to do, where the law puts us, and what the whole thing runs on.
Authentication & access
- Sign-in, two-factor and session controls
- You sign in with an email address and a password, checked against a password policy. An organization admin can require TOTP two-factor authentication, limit access to an IP allow list, and set an inactivity timeout of up to 24 hours. All three are enforced by the server on every API request, not just in the browser. Single sign-on (Google Workspace or SAML) is not built yet.
- Multi-tenant data isolation
- Your leads, prompts, embeddings, and knowledge base are isolated per workspace. Every query is scoped to your workspace and fails closed, a request without workspace context returns nothing rather than everything.
- Scoped integration tokens
- CRM and mailbox connections use the OAuth scopes you approve, and nothing wider. You can revoke them from the provider at any time without going through us.
AI safety & email guardrails
- Grounded generation and guardrails
- The AI SDR pipeline runs against hardcoded prompt guardrails and writes from your knowledge base and your brand guidelines, so it works from your material rather than inventing product claims to fill a paragraph. Each draft is scored for confidence, and low-confidence output is held for review rather than sent.
- No model training on your data
- Lazure does not train or fine-tune any model on your files, your prospect interactions, or your system data. Your documents are retrieved at the moment a message is drafted; they are never built into a model.
- Sends are gated, not fired
- Sending an email is treated as irreversible. In agentic mode it is gated for human approval at every autonomy level, including the most autonomous one. In Smart Mode, whether a reply is held for one-click approval or sent automatically is configurable per workflow. Email sent through a mailbox you connect goes from that mailbox. Sequence email sent through our email provider goes from your own address once your domain is verified with us; until then it goes from a Lazure sender address, with your address as the reply-to.
Global privacy compliance
- GDPR, DPAs, and published retention windows
- We are putting a DPA in place with each of our own subprocessors, and we provide you a formal DPA, covering our deletion policy and the full subprocessor list, on request. Our retention policy keeps prompt and draft content, the text of a message and the context used to write it, for 30 days, then deletes it. The decision record for that message, which model wrote it and who approved it, is kept for 24 months so audit questions can be answered after the content is gone.
- Your right to object
- If we hold data about you that we obtained from an enrichment provider rather than from you, you can object. We erase the profile, not just stop emailing you, and keep only the minimal record needed to make sure you are not re-added.
- We never sell prospect data
- Data gathered during your outreach campaigns is never sold, rented, or monetised. It is not pooled into a shared dataset for other customers to prospect against.
- Deletion on request
- Ask us to delete your workspace data and we delete it, conversations, drafts, knowledge base, embeddings and AI decision records. It is a hard delete, not a deactivation flag, and we return a receipt showing what was removed. The specifics are written into the DPA rather than left to a support ticket.
Infrastructure & hosting
- Hosted on SOC 2 Type II certified infrastructure
- Lazure is deployed across Vercel and Railway, on AWS infrastructure certified to SOC 2 Type II. That certification is theirs, not ours, what we inherit from it is the physical, network, and data-centre security underneath us.
- Encryption in transit and at rest
- Everything moving between your CRM and Lazure is encrypted with TLS, and we send HSTS so browsers refuse to fall back to plain HTTP. Data at rest is encrypted with AES-256 at the storage layer by our hosting providers. Stored integration credentials are additionally encrypted at the application layer, so a database dump alone does not yield your CRM tokens.
- Deployment pipeline
- Every change runs through automated tests, secret scanning, and dependency vulnerability scanning in CI. CI does not yet block a deploy.
Where your data actually goes. Destination by destination.
If your security review needs this as a diagram for a questionnaire, ask and we will send one.
