Security & Data Privacy

Your engineering files are processed in memory and discarded after the response by default. Storage is opt-in, admin-controlled, and deletable at any time โ€” you stay in control of your data.

Transient by Default Encrypted in Transit (HTTPS/TLS) Opt-In Storage, Admin-Controlled Delete Anytime Not Used to Train AI

๐Ÿ”’ Transient by Default โ€” You Control What's Stored

Every file you upload to AIDC โ€” PLC code, P&ID drawings, network configurations, EPMS data โ€” is processed in memory and discarded after the response. Nothing is written to file storage or the search index unless a tenant admin explicitly opts in to Document Vault or the persistent Knowledge Base. When you do opt in, you can delete any single file, your entire vault or knowledge base, or purge all of your data at any time โ€” deletion cascades across files, metadata, index chunks, and knowledge-graph edges and is irreversible. Billing and invoice records are retained for tax compliance.

๐Ÿง 
Not Used to Train AI Models
Your files are processed only to serve your requests. L2 and L3 features use the Anthropic Claude API; your content is not used to train AI models. L1 reviews are deterministic rule engines that run in our own environment.
๐Ÿ”
Encrypted in Transit & at Rest
All traffic between your browser and AIDC is encrypted in transit over HTTPS/TLS. Data you choose to store is encrypted at rest using our cloud provider's default encryption. AIDC is hosted in the Tokyo (asia-northeast1) region.
๐Ÿ“‹
Immutable Audit Trail
Sensitive actions โ€” deletions, consent changes, and billing events โ€” are recorded to an append-only audit trail with timestamp, user ID, and tenant ID. Your uploaded file contents are never written to this trail.
๐Ÿ”‘
Opt-In Storage, Admin-Controlled
Document Vault (file storage) and the persistent Knowledge Base (searchable index) are OFF by default. They can only be enabled by a tenant admin, and each consent is recorded to an append-only audit log. You can delete a single file, your whole vault or knowledge base, or purge all your data in one action at any time โ€” deletion is irreversible.
๐ŸŒ
Isolated to Your Tenant
Every read, write, and delete is scoped to your authenticated tenant ID, taken from your session and never from request input. There is no cross-tenant access to your files, metadata, or index.
โš™๏ธ
On-Prem / Air-Gapped Deployment
For Enterprise and Platform tiers, AIDC can be deployed inside your own network or VPC, where inference runs within your environment. Available as a deployment option โ€” contact us to discuss requirements.
What We Store โ€” and What's Opt-In
By default nothing you upload is persisted. Storage is opt-in, admin-controlled, and deletable at any time.
Data TypeStored?WhereRetention
Uploaded files (default)No โ€” transientProcessed in memory, discarded after responseUntil the response completes
Original files with Document Vault (opt-in)Only if enabled by your adminEncrypted file storage, Tokyo regionUntil you delete them
Parsed text with Knowledge Base (opt-in)Only if enabled by your adminSearchable index, Tokyo regionUntil you delete it
AI prompts and responsesNot stored by AIDCProcessed to serve your requestNot retained by AIDC
Account information (name, email, company)YesManaged cloud database, Tokyo regionUntil account deletion
Billing & audit recordsYesManaged cloud database, Tokyo regionRetained for tax & compliance
Session tokens (JWT)YesBrowser cookie only30 days or logout
NDA & Data Protection Process
For enterprise customers who require formal agreements before sharing proprietary files.
Mutual NDA Available
LGC provides a standard mutual NDA covering PLC code, P&ID drawings, network configurations, and all engineering assets as confidential information. Available for signature before any file upload. Contact: info@lgc.inc
Enterprise Data Processing Agreement
A full Data Processing Agreement (DPA) aligned to GDPR principles and Japan APPI is available for Enterprise and Platform tier customers. Covers sub-processor relationships, breach notification, and data subject rights.
Compliance Roadmap
SOC 2 Type II audit in progress (target: Q3 2026). IEC 62443 alignment built into the platform architecture. SEMI E187 pre-certification is an L1 built-in tool. ISO 27001 planned for 2027.

Questions about security?

Contact our security team: info@lgc.inc โ€” we respond to all security inquiries within 24 hours. For enterprise pilots and NDA requests, we can typically turn around documentation within 48 hours.