Trust
Security at Locket
How we design, build, and operate Locket to keep customer data protected and Sophei's outputs trustworthy.
Security is not a checklist for us, it's a design constraint on every feature. This page summarizes the practices behind Locket's platform, from network isolation to how Sophei handles sensitive data.
Our security posture
- SOC 2 Type II, audit in progress with a Big Four firm
- GDPR and UK GDPR aligned, DPA available on request
- CCPA compliant, data subject requests handled from the admin console
- Continuous security monitoring, quarterly penetration tests, annual tabletop exercises
Encryption
All data in transit is encrypted with TLS 1.2+ and modern cipher suites. All data at rest is encrypted with AES-256, with keys managed in AWS KMS and rotated on a rolling schedule. Field-level encryption is applied to secrets such as third-party API tokens.
Workspace isolation
Every workspace runs under strict logical isolation: application-layer authorization checks on every request, per-workspace database row-level security, and per-workspace inference contexts. Sophei cannot see or reference data from other workspaces.
Access control
- Role-based access control with least-privilege defaults
- SSO/SAML available on Pro and Enterprise plans
- Just-in-time engineering access with audit logging and time bounds
- Sensitive actions require multi-factor authentication
AI safety and integrity
Every Sophei generation runs through a two-stage guardrail: a policy classifier that checks for prohibited content, and a voice guardrail that checks alignment with your locked brand profile. Anything that fails is queued for human review rather than shipped.
- Prompt injection defenses against untrusted upstream text (Klaviyo notes, product descriptions, etc.)
- PII redaction before content ever reaches model providers
- Model-provider agreements prohibit training on your data
- Full audit trail of every Sophei generation, prompt, and approval decision
Infrastructure
Locket runs on AWS in US-East and EU-West. Production environments are network-isolated from staging and development, and are only reachable from authenticated services. We use immutable, container-based deployments with signed images and continuous vulnerability scanning.
Reliability and backups
- Automated encrypted backups: daily full, hourly incremental
- RTO of 4 hours and RPO of 1 hour for the primary datastore
- Multi-AZ failover for our application tier
- Public status page at status.locketailabs.com
Responsible disclosure
If you believe you've found a vulnerability, please email security@locketailabs.com with details and a proof of concept. We commit to acknowledging within 24 hours and, where appropriate, offering a bounty. We do not pursue legal action against good-faith researchers.
Contact
For enterprise security reviews, DPAs, or a security questionnaire, reach out to security@locketailabs.com.
Related documents
Ready to market with intelligence?
Join hundreds of brand teams turning customer behavior into campaigns their audience actually wants. Setup in under 24 hours.