Data privacy & the no-training policy
Your documents are never used to train public models, and Nigerian data-protection handling (NDPA 2023) is built into the platform.
- No-training policy — your uploaded agreements, review outputs, and playbook rules are never used to train public LLM models. On the cloud tier, model context is used only to process your request, not retained for training; the sovereignty tier keeps everything on local models.
- Nigerian data-protection handling — LexCore is designed around the Nigeria Data Protection Act 2023 (NDPA), the primary statute, supervised by the NDPC — with the earlier NDPR 2019 still relevant as subsidiary instrument: access controls, data-residency options, and simple deletion on request. Formal certification is on the roadmap and is not claimed as complete.
- PII redaction in logs — emails and long digit runs are masked before text reaches a log sink, as defence-in-depth for privileged data.
- No-store free scan — the public scanner does not retain the document you test with.
Trust
For the strongest guarantee, a self-hosted sovereign deployment runs the whole stack on your own infrastructure, so document bytes and model calls stay inside your network boundary. On LexCore-hosted plans the sovereignty tier keeps model inference local; storage remains on LexCore-operated infrastructure.
Related technical documentation
Security architecture: isolation, encryption & access
Tenant isolation enforced at both the app and database layers, AES-256 encryption with KMS key sourcing, and role- plus MFA-gated access.
Your data controls: export, deletion & MFA
The table-stakes controls a data-privacy review expects — version history, export, permanent erasure, account purge, and step-up MFA.
Data sovereignty & model routing
How the model router keeps a sovereign tenant's documents away from third-party model providers — and why where your ANALYTICS goes is a separate question with its own control.