Data minimization
Lynx Labs limits client data to what an engagement requires, and keeps it only for that work and for legal duties that apply. This website does not ask for accounts or form submissions. It does not collect personal data beyond messages sent by email.
Encryption
Client data handled by Lynx Labs is encrypted in transit with TLS and encrypted at rest.
Least privilege
Lynx Labs applies the principle of least privilege to client work. A person receives access only to the systems their work requires. An integration requests only the data and permissions that engagement needs. Access is removed when it is no longer needed.
Access control
Access to systems that store client data is limited to people who need it for their work. That access requires multi-factor authentication, and it is removed when it is no longer needed.
Vendors
Before a vendor processes client data for Lynx Labs, Lynx Labs puts a business associate agreement in place when the work requires one.
Incidents
If Lynx Labs learns of a security incident affecting client data, it notifies the affected client and cooperates on containment and remediation. Further steps follow the client agreement and applicable law. This page does not promise a specific response time or outcome.
Business associate agreements
Lynx Labs builds with HIPAA requirements in mind. Where a client is a covered entity and the work requires it, Lynx Labs signs a Business Associate Agreement. This page is not a certification of any system.
Report a security issue
Email security@lynxlabs.dev. Describe the issue and how to reproduce it. Do not include patient information or other sensitive client data in the report.
