Security & trust

Posture you can audit.

Ligarbo inherits the HexxLock platform's tier-1 security baseline. DPA, sub-processor list, and CSF mapping are available on request.

The items below describe our architecture and operating practice. None carry an independent third-party audit or certification yet — see Compliance below for what is and isn't certified today.

Encryption

TLS 1.3 at the edge. mTLS between services in the cluster.

Tenant isolation

Row-level security on every customer table.

Audit

Every privileged action is logged.

Compliance

We operate with GDPR obligations in mind. No SOC 2 or ISO 27001 report exists yet; both are on our roadmap and not currently certified.

Data residency

We run on self-hosted infrastructure rather than a public cloud region. A formal, contractual data-residency commitment is not yet published — contact us if this is a requirement for your organization.

Vulnerability program

Daily Trivy scans.

Sub-processors

We will publish the current sub-processor list here before launch. The list will include Cloudflare (edge + DDoS), iyzico (billing), LinkedIn (advertising), Meta (advertising + messaging), Anthropic (AI gateway). Any change is notified to customers 30 days in advance.