Security is our priority
Version 1.3 · Effective date: July 9, 2026 · Last updated: July 9, 2026
Security Architecture
Multi-layered protection for your data using modern security standards
The measures described reflect our approach as of the effective date of this document; certain controls are available on eligible plans and may be rolled out in phases and evolve.
Data Encryption
Data is protected in transit and in backups; sensitive secrets are stored encrypted.
Tenant Isolation
Each client's data is logically isolated through application controls: mandatory tenant-scoped filtering of all queries and cross-tenant isolation tests in CI.
Authentication
Sign-in with email and password or Google (OAuth); enterprise SSO (OIDC) on eligible plans. One-time email codes are used for address verification and password reset.
Access Control (RBAC)
Flexible role and permission system with control at the category and item level.
Audit Log
Logging of key actions with history retention for regulatory compliance.
Network Security
Anti-DDoS protection at the OVHcloud infrastructure level; application-level rate limiting; network access to the database is restricted by IP (allowlist).
AI and Data Security
Your data remains yours. LiKE uses AI exclusively to improve search within your workspace.
Your workspace's data only
Tenant data is used ONLY to provide answers within that tenant
Not used for training
Data is NOT used for training or optimizing LLM models (details in the AI Supplementary Terms, /en/ai-terms.html)
Encrypted channels
All LLM requests are transmitted through encrypted channels with namespace isolation
No cross-tenant leaks
Pipeline space parameter provides data isolation at the search-pipeline architecture level
Infrastructure and Data Storage
Reliable and scalable infrastructure with automatic backups and disaster recovery plan
Data Centers
- OVHcloud (EU)
- Customer data is stored in the EU
- Infrastructure across two EU locations (Frankfurt — application, Gravelines — database); daily backups with point-in-time recovery
- Availability monitoring and incident response
Database
- PostgreSQL on an isolated database host (TLS 1.3, IP-allowlist); backups are encrypted (PGP); integration secrets are stored encrypted
- pgvector for embeddings
- Automatic indexing
- Query optimization
Cache Layer
- High-performance caching
- Temporary data and rate limits
- Rate limiting
Backups
- Daily backups
- Backups retained for about 30 days (7 daily + 4 weekly snapshots); plus point-in-time recovery (PITR) for the last several days
- Point-in-time recovery
- Restore from backups is periodically verified against real data; results are recorded
Disaster Recovery
- Internal RTO/RPO targets; contractual recovery commitments under a separate agreement (Enterprise)
- Periodic restore verification
Monitoring
- Automated system monitoring
- Automated alerts
- Performance metrics
- A defined incident response process
Compliance Roadmap
Our commitment to meeting the strictest security and privacy standards
SOC 2 Type II — on our roadmap (target: Q3 2026, after stabilization of the beta program).
ISO 27001 — on our roadmap (target: Q4 2026, starting after SOC 2).
We currently hold no certifications; we publish only statuses that have actually been achieved.
Responsible Vulnerability Disclosure
If you have discovered a potential security vulnerability, please report it to us responsibly
Reporting Process
Vulnerability reports: [email protected]. We do not pursue good-faith researchers acting within responsible disclosure (no DoS load, no access to other users' data, 90-day non-disclosure period; safe-harbor details in the Beta Testing Program Agreement, §5.8).
Important: Please do not disclose vulnerabilities publicly until we have released a fix. This helps protect all LiKE users. We acknowledge and thank researchers who responsibly disclose vulnerabilities.