Trust & Data Protection
Security at The Shell
Your firm's correspondence is privileged. The Shell is built so that the words you write stay yours — processed, formatted, and dispatched without being kept.
Last updated · September 2026
01 — Your Content
What we store, and what we don't
- Letter contents are not retained. Once a letter is dispatched, its body text is not stored on our servers. Drafts remain in your browser until you send.
- What we do keep: your account and firm identity, the branding assets you upload (logo, signature, seal), and a metadata-only dispatch record — recipient, subject line, jurisdiction, timestamp, and an assist / edit / approval trail. Never the letter itself.
- Deletion on request. You can ask us to delete your account and its associated data at any time.
02 — AI Processing
How AI touches your work
- Commercial terms only. Drafting and refinement run through third-party AI providers under commercial API agreements that prohibit training models on your content.
- Not retained for training. Your text is used to answer the request and is not kept by the providers to improve their models.
- A human always signs off. The platform will not dispatch a letter until you have reviewed it and confirmed you take responsibility for sending it. Every AI-drafted contract carries a review-required notice.
03 — Encryption & Transport
Data in motion and at rest
- In transit: all traffic is encrypted with modern TLS. The domain is on the HSTS preload list, so browsers refuse to connect over plain HTTP.
- At rest: stored data is encrypted by our infrastructure providers.
- Hardened responses: a strict Content-Security-Policy, X-Frame-Options: DENY, nosniff, and a locked-down permissions policy are enforced on every request.
04 — Authentication & Access
Who can reach your data
- Passwords are stored using PBKDF2 key derivation with a per-user salt and a high iteration count — never in plain text, never as a bare hash.
- Sign in with Google is supported; the identity token is verified on our servers.
- Sessions use short-lived signed tokens.
- Brute-force resistance: sign-in, password-reset, and other sensitive endpoints are rate-limited.
- Isolation: every firm's records are scoped to its own authenticated session; the application enforces least-privilege access throughout.
05 — Infrastructure & Availability
Where it runs
- Enterprise cloud. The Shell runs on established cloud infrastructure with automated backups and point-in-time recovery.
- Provider detail on request. For security reasons we do not publish the specifics of our hosting, database, and processing providers. The full subprocessor register is shared with prospective and current customers — see below.
06 — Vulnerability Management
Keeping it current
- Dependencies are continuously monitored for known vulnerabilities and patched.
- The codebase undergoes periodic security review.
- Found something? Email security@lyonshub.com — we investigate every report and will keep you updated.
07 — Incident Response
If something goes wrong
- In the event of a confirmed security incident affecting your data, we will notify you promptly and in accordance with applicable law — including PIPEDA in Canada and equivalent regimes where they apply.
08 — Compliance Posture
Where we stand
- The Shell is engineered to the control principles of SOC 2 — security, availability, and confidentiality. Formal certification is on our roadmap.
- Our controls documentation, subprocessor register, completed security questionnaires (CAIQ-Lite / SIG-Lite), and Data Processing Agreement are available to prospective and current customers on request, under NDA.
For Reviewers
Reviewing The Shell for your firm?
The following are shared directly with prospective customers rather than published. Publishing a detailed map of our infrastructure would only help the wrong people — so we send it to the people who actually need it.
- Named subprocessor register — every third-party service and its role
- Full controls documentation
- Completed CAIQ-Lite / SIG-Lite security questionnaire
- Data Processing Agreement (DPA)
- Architecture overview
Request the documentation →
We respond within two business days.