Trust

Security at Locket

How we design, build, and operate Locket to keep customer data protected and Sophei's outputs trustworthy.

Effective January 15, 2026Last updated January 15, 2026

Security is not a checklist for us, it's a design constraint on every feature. This page summarizes the practices behind Locket's platform, from network isolation to how Sophei handles sensitive data.

Our security posture

  • SOC 2 Type II, audit in progress with a Big Four firm
  • GDPR and UK GDPR aligned, DPA available on request
  • CCPA compliant, data subject requests handled from the admin console
  • Continuous security monitoring, quarterly penetration tests, annual tabletop exercises

Encryption

All data in transit is encrypted with TLS 1.2+ and modern cipher suites. All data at rest is encrypted with AES-256, with keys managed in AWS KMS and rotated on a rolling schedule. Field-level encryption is applied to secrets such as third-party API tokens.

Workspace isolation

Every workspace runs under strict logical isolation: application-layer authorization checks on every request, per-workspace database row-level security, and per-workspace inference contexts. Sophei cannot see or reference data from other workspaces.

Access control

  • Role-based access control with least-privilege defaults
  • SSO/SAML available on Pro and Enterprise plans
  • Just-in-time engineering access with audit logging and time bounds
  • Sensitive actions require multi-factor authentication

AI safety and integrity

Every Sophei generation runs through a two-stage guardrail: a policy classifier that checks for prohibited content, and a voice guardrail that checks alignment with your locked brand profile. Anything that fails is queued for human review rather than shipped.

  • Prompt injection defenses against untrusted upstream text (Klaviyo notes, product descriptions, etc.)
  • PII redaction before content ever reaches model providers
  • Model-provider agreements prohibit training on your data
  • Full audit trail of every Sophei generation, prompt, and approval decision

Infrastructure

Locket runs on AWS in US-East and EU-West. Production environments are network-isolated from staging and development, and are only reachable from authenticated services. We use immutable, container-based deployments with signed images and continuous vulnerability scanning.

Reliability and backups

  • Automated encrypted backups: daily full, hourly incremental
  • RTO of 4 hours and RPO of 1 hour for the primary datastore
  • Multi-AZ failover for our application tier
  • Public status page at status.locketailabs.com

Responsible disclosure

If you believe you've found a vulnerability, please email security@locketailabs.com with details and a proof of concept. We commit to acknowledging within 24 hours and, where appropriate, offering a bounty. We do not pursue legal action against good-faith researchers.

Contact

For enterprise security reviews, DPAs, or a security questionnaire, reach out to security@locketailabs.com.

Start free

Ready to market with intelligence?

Join hundreds of brand teams turning customer behavior into campaigns their audience actually wants. Setup in under 24 hours.