Home / Legal / Security is our priority

Security is our priority

Version 1.3 · Effective date: July 9, 2026 · Last updated: July 9, 2026

Security Architecture

Multi-layered protection for your data using modern security standards

The measures described reflect our approach as of the effective date of this document; certain controls are available on eligible plans and may be rolled out in phases and evolve.

Data Encryption

Data is protected in transit and in backups; sensitive secrets are stored encrypted.

Tenant Isolation

Each client's data is logically isolated through application controls: mandatory tenant-scoped filtering of all queries and cross-tenant isolation tests in CI.

Authentication

Sign-in with email and password or Google (OAuth); enterprise SSO (OIDC) on eligible plans. One-time email codes are used for address verification and password reset.

Access Control (RBAC)

Flexible role and permission system with control at the category and item level.

Audit Log

Logging of key actions with history retention for regulatory compliance.

Network Security

Anti-DDoS protection at the OVHcloud infrastructure level; application-level rate limiting; network access to the database is restricted by IP (allowlist).

AI and Data Security

Your data remains yours. LiKE uses AI exclusively to improve search within your workspace.

Your workspace's data only

Tenant data is used ONLY to provide answers within that tenant

Not used for training

Data is NOT used for training or optimizing LLM models (details in the AI Supplementary Terms, /en/ai-terms.html)

Encrypted channels

All LLM requests are transmitted through encrypted channels with namespace isolation

No cross-tenant leaks

Pipeline space parameter provides data isolation at the search-pipeline architecture level

Infrastructure and Data Storage

Reliable and scalable infrastructure with automatic backups and disaster recovery plan

Data Centers

  • OVHcloud (EU)
  • Customer data is stored in the EU
  • Infrastructure across two EU locations (Frankfurt — application, Gravelines — database); daily backups with point-in-time recovery
  • Availability monitoring and incident response

Database

  • PostgreSQL on an isolated database host (TLS 1.3, IP-allowlist); backups are encrypted (PGP); integration secrets are stored encrypted
  • pgvector for embeddings
  • Automatic indexing
  • Query optimization

Cache Layer

  • High-performance caching
  • Temporary data and rate limits
  • Rate limiting

Backups

  • Daily backups
  • Backups retained for about 30 days (7 daily + 4 weekly snapshots); plus point-in-time recovery (PITR) for the last several days
  • Point-in-time recovery
  • Restore from backups is periodically verified against real data; results are recorded

Disaster Recovery

  • Internal RTO/RPO targets; contractual recovery commitments under a separate agreement (Enterprise)
  • Periodic restore verification

Monitoring

  • Automated system monitoring
  • Automated alerts
  • Performance metrics
  • A defined incident response process

Compliance Roadmap

Our commitment to meeting the strictest security and privacy standards

SOC 2 Type II — on our roadmap (target: Q3 2026, after stabilization of the beta program).

ISO 27001 — on our roadmap (target: Q4 2026, starting after SOC 2).

We currently hold no certifications; we publish only statuses that have actually been achieved.

Responsible Vulnerability Disclosure

If you have discovered a potential security vulnerability, please report it to us responsibly

Reporting Process

Vulnerability reports: [email protected]. We do not pursue good-faith researchers acting within responsible disclosure (no DoS load, no access to other users' data, 90-day non-disclosure period; safe-harbor details in the Beta Testing Program Agreement, §5.8).

Important: Please do not disclose vulnerabilities publicly until we have released a fix. This helps protect all LiKE users. We acknowledge and thank researchers who responsibly disclose vulnerabilities.

Version 1.3, effective from 2026-07-09