Security, data residency and the DPA — plainly.
LEXUN's honest security advantage is architectural: by default your decision data never reaches us, because analysis runs in your browser and is stored on your device. This page states exactly what that means, what our infrastructure does process, and what we can and cannot yet sign.
Architecture
- Local-first processing — the simulation engine runs entirely client-side. Inputs, forecasts, outcomes and the audit trail live in your browser's local storage. There is no LEXUN database of user decisions. LIVE
- Transport security — all pages served over HTTPS with strict transport security. LIVE
- No third-party trackers — no advertising pixels, no cross-site cookies, no third-party analytics scripts. The full storage-key inventory is in the Cookie Policy. LIVE
What is processed server-side today
| Data | Processor | Location | Purpose |
|---|---|---|---|
| Standard web-server logs (IP, user-agent, request path) | Netlify, Inc. (hosting/CDN) | Global CDN; primary infrastructure in the US/EU | Serving the site; security; reliability |
| Waitlist email address (only if you submit the form) | Netlify Forms | US/EU | Emailing you about launches, with consent |
That is the complete list. There are no other sub-processors because there is no other server-side processing.
Data residency
Honestly stated: your decision data resides on your own device, in your jurisdiction, by construction. Static site assets are served from a global CDN. We do not currently offer UK-only or EU-only hosting commitments because we do not host user decision data at all; if future sync features change this, residency options will be published here before launch, not after.
Data Processing Agreement
For organisations that require a signed DPA under UK GDPR Article 28: because LEXUN does not process your decision data server-side, a conventional controller–processor DPA covers only the narrow scope above (hosting logs, waitlist contact). We will provide and sign a DPA reflecting that scope on request — email hello@lexun.co.uk. When hosted sync and team features ship, an expanded DPA with the full sub-processor list will be published on this page first. ON REQUEST
What we will not claim
No SSO, no SOC 2 report, no penetration-test certificate exists today, and we won't imply otherwise — capability status is tracked openly on the Organisations page. A security claim you cannot verify is worth exactly as much as an accuracy claim you cannot verify.
Reporting a vulnerability
Email hello@lexun.co.uk with "Security" in the subject. We commit to acknowledging reports within 5 working days.