You’re trusting us with the information that drives your organization’s funding — and with data about the people you serve. Here is exactly how that trust is built, in plain language, including the limits. Everything on this page is either live and tested in our platform today or clearly marked as rolling out — because trust built on overstatement isn’t trust.
Or read the public Subprocessor Disclosure.
Names and contact details of the people you serve are the most sensitive data you hold, and often legally protected. Our answer: we’re built so we don’t hold them in any form our team can read.
Your grant pipeline, briefs, and financials are competitively vital, and you need us to work with them. Our answer: least-privilege access you can watch.
When someone fills out one of your forms, any identifying fields are split off at the moment of collection into a separate identity vault, and the working record gets a code (like P-4X7K2). Everything downstream — analysis, reporting, drafting — runs on codes.
Good rules need enforcement, so the platform screens everything on the way in. Every request, note, and file upload is checked server-side for participant-identifying patterns — lists of names, SSNs, date-of-birth columns, contact-sheet spreadsheets. Flagged items are rejected before anything is stored: nothing lands, even briefly. The rejection explains what was detected and shows the right path (coded forms, or a de-identified re-upload). PDF and image files can’t be content-screened, so uploading one requires you to confirm it contains no participant-identifying information — an honest limit, stated at the moment it matters.
Our platform runs on Supabase (database) and Vercel (application), encrypted in transit and at rest — the same class of infrastructure behind most modern software you already use. We’re not “in-house” — and honestly, neither are the spreadsheets, form tools, and email your data lives in today. The real question is whose controls are stronger. Ours are listed on this page, and they’re verifiable. If a funder requires your data to live somewhere specific, tell us — we’ll structure around it, working only from coded or aggregate exports. We’d rather narrow scope than put your funding at risk.
Two things we want you to understand precisely, because trust built on overstatement isn’t trust:
A Data Processing Agreement (data classes, prohibited uses, a 72-hour breach-notification commitment, deletion schedules), an AI Disclosure, an Acceptable Use Policy, and — for HIPAA covered entities — a Business Associate Agreement. Our current subprocessor list is public. Ask us for any of it before you sign anything.
Questions, or want the Security & Compliance overview for your board or auditor? support@lilxhub.com.