How we protect the information you trust us with, and how to report a problem. This is a beta draft pending legal review. No system is perfectly secure; we aim to be honest about what we do.
How we protect data
- Less to protect. Raw chat and audio stay on the PC. Ordinary conversations are never stored in the cloud. What we do store has short retention limits.
- In transit and at rest. Everything travels over HTTPS. Screenshots buffered on the PC are encrypted with a key only that Windows account can use.
- Accounts. Passwords are stored with PBKDF2-SHA256 (at least 210,000 iterations). Sessions use secure, HttpOnly cookies, and changes made from a browser are checked against the site's origin. Your email must be verified before pairing or notifications.
- Devices. Each PC gets a random 256-bit token that we store only as a hash. Revoking a device or guardian authority stops it immediately.
- No chat in logs. We do not write chat text to logs or notifications.
- Secrets are kept in encrypted configuration, not in code.
- Monitoring and rate limits protect against abuse and guessing.
- Providers. We use a small set of providers, listed on the subprocessors page, and require no-retention, no-training handling for AI processing.
What we have not done yet
We have not yet had an independent security assessment or certification. We plan one before general availability, and we will say so here when it happens.
Reporting a vulnerability
Email security@lantore.com with details (and, if you can, steps to reproduce). Please do not access other people's data, and give us reasonable time to fix a problem before sharing it. We will acknowledge your report within three working days. Our contact details are also published in security.txt.
If something goes wrong
If a security incident affects your information, we will tell you promptly, what happened, what it means for you, and what we are doing about it.