TRUST & RESPONSIBLE AI

Trust has to be designed before scale.

Lertsma is still early. These principles define how we intend to approach customer information and AI-assisted operational work as the product develops.

01

Data minimization

Collect and retain only the information needed for the intended workflow. Production retention policies will be documented as the service matures.

02

Server-side secrets

API credentials should remain server-side and never be embedded in client-side code or public repositories.

03

Grounded outputs

The product should surface missing information and uncertainty rather than silently filling gaps with unsupported assumptions.

04

Human review

High-impact legal, financial, compliance, employment, or other consequential decisions should receive appropriate human or professional review.

05

Access controls

As the product moves beyond private MVP use, authentication, role-based access, and auditability are planned requirements.

06

Evaluation before automation

We intend to evaluate factuality, task completion, uncertainty handling, and operational usefulness before expanding automation.

CURRENT STATUS

Early MVP, not a security certification.

This page describes product principles and planned controls. Lertsma Labs does not currently claim SOC 2, ISO 27001, penetration-test certification, or other third-party security certifications.