Security architecture Published
Cipher and key-derivation parameters, where the key exists and where it does not, what a sealed vault discloses before a token is entered, how a recipient verifies a production without depending on us, and a plainly stated list of the design's limitations.
Read the security architecture →
Company identity & security contact Published
L-VAULT is operated by Pink Viper Labs. It is in closed beta: there is no access request process, and the addresses below are for security and documentation only.
| Purpose | Contact |
|---|---|
| Vulnerability reports | security@l-vault.com |
| Documentation requests | security@l-vault.com |
Researchers acting in good faith will not be pursued. We will confirm receipt of a report and tell you what we intend to do about it.
Privacy, retention & deletion On request
What is stored, for how long, how deletion is carried out, and what remains afterwards. What can be stated now without qualification is architectural rather than contractual: the service holds ciphertext and an encrypted manifest, it does not hold access tokens or derived keys, and it runs no analytics or third-party trackers of any kind.
Retention periods and the deletion commitments that go with them are confirmed in writing before onboarding. Request the document →
Terms of service On request
Contractual terms, limitations of liability, and the service commitments made to a firm. Request the current terms →
Subprocessors & data location On request
Every third party in the path, what each can see, and the jurisdiction data rests in. The current deployment uses a dedicated-server hosting provider, an ACME certificate authority, and a webfont origin; no third party is in a position to read vault content, which is encrypted before it leaves the producing party's browser.
The definitive list, with entity names and hosting region, is provided on request — including for firms whose own policies require a zero-third-party-request deployment. Request the list →
Incident response On request
Detection, escalation, notification timelines, and what a firm is told and when. Request the plan →
HIPAA & BAA position On request
Matters involving medical records raise the question directly, so it is answered directly rather than implied. L-VAULT makes no claim of HIPAA compliance on this website, and no statement here should be read as one. The current position on protected health information and on executing a Business Associate Agreement is confirmed in writing before any matter involving PHI is onboarded. Ask before you upload →
On what this page does not say
No third-party audit, penetration test or certification is claimed, because none is currently held. L-VAULT is in closed beta and is not represented as a generally available service. Where a document is marked on request, it is because it is sent under NDA during onboarding — not because a claim is being made and withheld.