Skip to main content

Security & Trust

1. Our Approach to Security

We protect customer data through a combination of secure infrastructure choices, product design decisions, and operational practices. Rather than building and certifying our own data centres, we have deliberately chosen infrastructure providers that each hold independent, audited security certifications — including SOC 2 Type II, ISO 27001, and PCI DSS Level 1.

This page is a transparency document, not a marketing pitch. We describe what is genuinely in place today, what relies on our certified providers, and what we are working toward. Where something is planned rather than implemented, we say so.

2. Infrastructure Security

Our platform runs entirely on third-party cloud infrastructure — we do not own or operate any physical servers or data centres.

  • Frontend hosting: Vercel (SOC 2 Type II certified)
  • Rendering compute: AWS Lambda via Remotion (SOC 2 Type II, ISO 27001, FedRAMP)
  • Primary database: Supabase managed PostgreSQL (SOC 2 Type II, GDPR DPA)
  • Media storage (audio, video, logos): Vercel Blob (SOC 2 Type II)
  • Video asset storage: AWS S3 (SOC 2 Type II, ISO 27001)
  • Authentication: Clerk (SOC 2 Type II, GDPR DPA)
  • Payments: Stripe (PCI DSS Level 1, SOC 2 Type II)
  • Avatar rendering: D-ID (SOC 2 Type II, GDPR DPA)

Each provider maintains its own comprehensive security programme. We link to their respective security pages rather than summarise controls we do not directly administer:

3. Data Encryption

3.1 At Rest

All data stored across our infrastructure is encrypted at rest by default:

  • Supabase (PostgreSQL): AES-256 encryption enabled by default
  • Vercel Blob (media files): AES-256 encryption enabled by default
  • AWS S3 (video assets): AES-256 Server-Side Encryption (SSE-S3) enabled by default
  • Backups are encrypted using the same standards as production data

3.2 In Transit

  • TLS 1.2 or higher is enforced for all connections to and from our platform
  • HTTP Strict Transport Security (HSTS) is enforced on lenera.ai via Vercel
  • Data in transit between Lenera AI application services and infrastructure providers uses encrypted connections

4. Authentication and Access Control

User authentication for the Lenera AI platform is managed entirely by Clerk, a SOC 2 Type II certified identity provider. Lenera AI does not store, hash, or handle passwords directly.

  • Supported login methods: Google OAuth, Apple OAuth, Microsoft OAuth
  • Enterprise customers: SSO/SAML available via Clerk
  • Multi-factor authentication: available through Clerk for all user accounts
  • Internal access to production systems (databases, cloud consoles) is controlled through role-based access and provider IAM policies

5. Data Handling

  • Customer Content is used solely to deliver the Service contracted for
  • Customer data is not used to train general-purpose AI models that are shared with or made available to other customers
  • Sub-processors are listed at lenera.ai/legal/subprocessors
  • DeepSeek: data may be processed in China. This is disclosed in full in our Sub-processor List. Customers with data residency requirements should review this disclosure before use.
  • D-ID: data processed in Israel and the USA. Israel holds an EU adequacy decision for the purposes of GDPR Chapter V transfers.

6. AI and Biometric Data

Lenera AI does not collect, store, or process biometric data.

  • The platform uses stock avatar characters from the D-ID library — these are synthetic, pre-built characters and are not derived from or trained on real individuals' biometric data
  • No face uploads are accepted or processed by the platform
  • No voiceprints or voice cloning are performed

If custom avatar or voice-cloning features are added in future, they will require explicit prior consent from affected individuals and will be documented in our Privacy Policy and Sub-processor List before launch.

7. Compliance Roadmap

We are transparent about the gap between our current state and formal certifications. Below is our current compliance posture and roadmap:

  • GDPR: DPA available for enterprise customers; Standard Contractual Clauses (SCCs) are incorporated in the Data Processing Agreements of our sub-processors processing EU personal data where available. Transfers to DeepSeek (China) involve additional risk disclosures; see our Sub-processor List at lenera.ai/legal/subprocessors.
  • CCPA: Privacy Policy addresses California consumer rights including right to know, delete, and opt out
  • SOC 2 Type I & II for Lenera AI (entity-level): planned — target 2027
  • ISO 27001 for Lenera AI (entity-level): planned — target 2027

8. Vulnerability Disclosure

We take security reports seriously and are committed to working with the security research community in good faith.

  • To report a security vulnerability or concern: email support@lenera.ai
  • We aim to acknowledge all reports within 5 business days and provide an update on our assessment and remediation plan
  • We do not pursue legal action against security researchers who discover and report issues in good faith and in accordance with responsible disclosure principles
  • We do not currently offer a formal bug bounty programme, but we appreciate and acknowledge responsible disclosures

9. Incident Response

We maintain an internal incident response plan that governs how we detect, contain, assess, and remediate security incidents.

  • In the event of a confirmed data breach or security incident that affects customer personal data, we will notify affected customers promptly and in accordance with applicable law
  • For incidents involving EU personal data, we assess GDPR Article 33 notification obligations (supervisory authority) and Article 34 obligations (data subject notification where required)
  • We will describe what happened, what data was involved, and what steps we are taking to address the issue
  • Security incidents can be reported to support@lenera.ai

10. Certifications Summary

The table below summarises our current security controls and certification status.

Control
Standard / Measure
Status
Encryption at Rest
AES-256 (via Supabase, Vercel Blob, AWS S3)
✓ In place via infrastructure providers
Encryption in Transit
TLS 1.2+ / HSTS
✓ In place via Vercel
Authentication
Clerk SOC 2 Type II certified IdP
✓ In place
Payment Security
Stripe PCI DSS Level 1
✓ In place
SOC 2 Type II
Via Vercel, AWS, Supabase, Stripe, Clerk
✓ Provider-level certifications
Lenera AI SOC 2 Type II
Planned
○ Target: 2027
ISO 27001
Planned
○ Target: 2027
GDPR
DPA available; SCCs incorporated in sub-processor agreements where available. DeepSeek (China) transfers involve additional risk disclosures; see lenera.ai/legal/subprocessors
✓ In place
EU AI Act
Transparency obligations (Art. 52): AI-generated content disclosure
✓ In place — disclosed in Terms of Service and Content Ownership Policy
Vulnerability Disclosure
Active — support@lenera.ai
✓ In place

Note: "Provider-level certifications" means the relevant certification is held by our infrastructure provider for the systems they operate on our behalf. Lenera AI entity-level certifications are planned for 2027.

11. Contact

Questions about our security practices? Contact us at support@lenera.ai.

Last updated: August 2026