Security and trust

You are handing us your unfixed accessibility findings.

That is a list of exactly where your products fall short, sometimes alongside documents containing client information. We treat it accordingly, and we are direct about what is in place today versus what is coming.

Where we stand today

No certification theatre. If something is in progress we say in progress, so you can weigh it against your own risk appetite.

In place

Encryption in transit and at rest

TLS 1.2 or higher on every connection. Data encrypted at rest with managed keys.

In place

Canadian data residency

Primary hosting in Canada. Available as a contractual commitment on Govern.

In place

SAML single sign-on

Available on Govern, with SCIM provisioning so leavers lose access with the rest of their tooling.

In place

Audit history

Who viewed, changed, or exported what, retained for the life of the account and exportable.

In progress

SOC 2 Type II

Readiness work underway. We will publish the report date when it is set rather than implying we hold one.

In progress

Penetration testing

First third-party test scheduled. The summary letter will be available under NDA once complete.

What we store, and what we do not.

The shortest version: we keep what is needed to show a finding and prove it was fixed, and nothing beyond that.

DataStoredRetention
Page markup and screenshotsThe evidence behind each findingYesWhile the finding is open, then 12 months
Uploaded documentsWord, Excel, PowerPoint, PDFYesUntil you delete them, or 30 days after account close
Findings and verdictsIncluding who signed off and whenYesLife of the account, for the compliance trail
Session credentials for auth testingCaptured browser session, never a passwordEncryptedUntil revoked or the session expires
Passwords for your systemsWe never ask for or accept theseNoNot applicable
Analytics on your end userslimena does not run on your live siteNoNot applicable
Free test inputsTested without an accountNoDiscarded after the result is shown

The free test stores nothing. A page or document tested without an account is processed in memory, the result is shown once, and it is discarded. Nothing is retained unless you create an account.

AI and your content

Your content is not training data.

limena uses AI to explain findings and draft fixes, which means content from your pages and documents is sent to a model provider.

This is the question every security reviewer asks, so here are the specifics rather than a reassurance.

  • No training on your data

    We use enterprise API tiers with training disabled by contract. Your content is not used to improve any model, ours or the provider’s.

  • Only what the finding needs

    The relevant element and its surrounding context, not the whole page or document. We do not bulk-send your content.

  • Providers are named

    Our sub-processor list is published and versioned. If it changes, existing customers are notified before the change takes effect.

  • You can turn it off

    AI explanations can be disabled per workspace. limena still detects and routes findings, you just get the standard criterion wording instead.

  • AI never signs off conformance

    A judgment call is always recorded against a person. This is a product principle, not only a security control.

Access, authentication, and the awkward one.

Testing an authenticated app means limena needs to get in. How that works matters more than any certificate.

Sessions, not passwords

For authenticated testing you capture a browser session and hand limena that. We never ask for a password, and we cannot reuse the session outside the scan.

Read-only by default

limena reads your product. Write access exists only where you explicitly connect a CMS or repo for auto-fix, and it is scoped to that.

Use a test account

We recommend a dedicated non-production account with representative permissions rather than a real user. Findings are identical.

Role-based access on your side

Unlimited seats does not mean unlimited visibility. Roles control who sees findings, evidence, and exports within your workspace.

For your security review

Send the questionnaire.

We would rather answer a real assessment than publish a badge. Send yours and we will complete it, including the questions where the answer is not yet.

Contact security

Available on request

  • Security questionnaire, completedOn request
  • Sub-processor listPublished
  • Data processing agreementOn request
  • Architecture and data flow summaryUnder NDA
  • Penetration test summaryWhen complete

Under NDA where appropriate. Enterprise agreements can include a security addendum and a defined incident notification window.

Questions we have not answered here?

Ask directly. We will give you a straight answer, including where the answer is that we are not there yet.