// Documentation

Everything a security review needs, in one place.

L-VAULT is in closed beta. Published documents are on this site; documents marked on request are sent under NDA during onboarding.

Security architecture Published

Cipher and key-derivation parameters, where the key exists and where it does not, what a sealed vault discloses before a token is entered, how a recipient verifies a production without depending on us, and a plainly stated list of the design's limitations.

Read the security architecture →

Company identity & security contact Published

L-VAULT is operated by Pink Viper Labs. It is in closed beta: there is no access request process, and the addresses below are for security and documentation only.

PurposeContact
Vulnerability reportssecurity@l-vault.com
Documentation requestssecurity@l-vault.com

Researchers acting in good faith will not be pursued. We will confirm receipt of a report and tell you what we intend to do about it.

Privacy, retention & deletion On request

What is stored, for how long, how deletion is carried out, and what remains afterwards. What can be stated now without qualification is architectural rather than contractual: the service holds ciphertext and an encrypted manifest, it does not hold access tokens or derived keys, and it runs no analytics or third-party trackers of any kind.

Retention periods and the deletion commitments that go with them are confirmed in writing before onboarding. Request the document →

Terms of service On request

Contractual terms, limitations of liability, and the service commitments made to a firm. Request the current terms →

Subprocessors & data location On request

Every third party in the path, what each can see, and the jurisdiction data rests in. The current deployment uses a dedicated-server hosting provider, an ACME certificate authority, and a webfont origin; no third party is in a position to read vault content, which is encrypted before it leaves the producing party's browser.

The definitive list, with entity names and hosting region, is provided on request — including for firms whose own policies require a zero-third-party-request deployment. Request the list →

Incident response On request

Detection, escalation, notification timelines, and what a firm is told and when. Request the plan →

HIPAA & BAA position On request

Matters involving medical records raise the question directly, so it is answered directly rather than implied. L-VAULT makes no claim of HIPAA compliance on this website, and no statement here should be read as one. The current position on protected health information and on executing a Business Associate Agreement is confirmed in writing before any matter involving PHI is onboarded. Ask before you upload →

On what this page does not say

No third-party audit, penetration test or certification is claimed, because none is currently held. L-VAULT is in closed beta and is not represented as a generally available service. Where a document is marked on request, it is because it is sent under NDA during onboarding — not because a claim is being made and withheld.