PolicyLenz.
Security & Trust

Built as if your security team designed it.

PolicyLenz analyzes the most sensitive documents an organization owns: its security policies. Every architectural decision below follows from that fact. This page is written for the security team doing the review; the one-pager below is yours to forward.

Data residency

Your documents stay yours, in both deployment models.

PolicyLenz is a sealed, single-tenant system in either of its two forms.Self-Hosted runs on your own infrastructure: a laptop, a VM, or your private cloud. Documents, analyses, scores, and the full history live in a database you own and never leave your network. PolicyLenz Cloud is a dedicated instance we provision and operate for one customer only: your documents live in that instance's own database, never in a shared platform, and you can export or delete everything at any time. In the Cloud AI edition the only outbound traffic is the model API call that powers analysis, governed by the egress controls below. The Self-Hosted Local edition runs the model on your own hardware and makes no AI calls at all.

Network egress

Default-deny, with a public ledger.

Every outbound request is checked against an allow-list before it happens. The default list contains exactly one host: api.anthropic.com. Anything else is refused, and every attempt, allowed or denied, is written to an egress ledger that administrators can inspect in the app. That is the Cloud AI edition; in the Local edition the engine runs on the host itself, appears in the same ledger as local engine calls, and no external AI host is allowed at all. TLS verification is mandatory and cannot be disabled. The application image ships no embedding, vector, or telemetry libraries; the Local edition adds one inference component (llama.cpp via Docker Model Runner) and one Ed25519-signed model file, both listed with checksums.

policylenz.internal/admin/egress
PolicyLenz egress log listing every outbound request to api.anthropic.com with allowed status
Supply chain

Updates you can verify, and undo.

Framework content updates arrive as offline bundles signed with Ed25519 and verified against a public key baked into your installation. Every file is hash-checked, version continuity is enforced (no skips, no downgrades), installs are atomic, and rollback is one click. Most importantly: bundles carry content only, never application behavior. An update can bring you a new control catalog; it can never bring you new code.

Access control

Roles that match how compliance teams actually work.

Five application roles

Admin, compliance manager, analyst, auditor, and viewer, each with an explicit capability set. Auditors read everything and write nothing; viewers cannot even download.

Three project roles

Lead, member, and viewer per project workspace, so client engagements and internal teams stay separated.

Invite-only onboarding

Expiring single-use invite links. No open registration, no self-service accounts.

TOTP MFA

Standard authenticator apps with recovery codes, enforceable org-wide for admins or for everyone.

Hardened session handling

Brute-force lockout, session management with instant revocation, and immediate session death on deactivation.

Last-admin protection

The system refuses to deactivate or demote the final active administrator. No lockout by accident.

Auditability

Auditors can reconstruct everything.

Policy versions are immutable. Runs pin the exact version they assessed and freeze their scope at creation, forever. Hard deletes are refused while any run holds a reference: the audit trail wins. Dispositions and evidence overlay results without ever rewriting the raw verdicts, remediation decisions are recorded per change with the decider's name, and an append-only audit log is filterable in the app by administrators and auditors.

Deployment

Facts your platform team will ask about.

  • Multi-arch image: amd64 and arm64
  • SQLite by default, Postgres via one environment variable
  • 266 automated tests, including migration and tamper-rejection coverage
  • Single published port; the backend is never directly exposed
  • Backend ships compiled, with no source in the image
  • Local edition: on-device engine verified against a signed manifest at install; Cloud AI edition: one allow-listed model host
What we don't claim yet

Candor is part of the security posture.

Certifications. PolicyLenz the company does not yet hold third-party certifications of its own. The product is built to the standards it assesses, and we will publish attestations as we earn them rather than implying them now.

Catalog text. NIST CSF 2.0 ships as verbatim official text. ISO/IEC 27001, SOC 2, and GDPR ship complete-coverage control objectives paraphrased by our team, with a verbatim overlay path for deployers who hold the relevant licenses. Complete coverage is guaranteed; the wording is disclosed for what it is.

Local edition. The on-device engine is a fine-tune of a 9-billion-parameter open-weight model. It is smaller and slower than the cloud model (about 12 minutes per framework for a 30-page policy on a 24 GB Apple Silicon Mac; suggestions are drafted on demand), its results can differ in places, and it needs an Apple Silicon Mac with 24 GB of memory or a Linux server; Windows is not supported yet. It needs internet once, at installation, for Docker's inference backend, and Docker Desktop requires a subscription for larger organizations (Docker Engine on Linux does not). The engine was trained on synthetic and public-domain policies with an open-weight teacher model, never on customer documents.

If any of these matters for your evaluation, we would rather discuss it on the first call than have you discover it after the purchase.

Bring your security team to the demo.

The architecture questions are usually the best part of the call.