Security

Designed to protect the access that protects your clients

Every credential in Lexful is encrypted at rest and in transit. Every access is logged. Your MSP's knowledge base should never become its weakest link.

AES-256 at rest
TLS 1.3 in transit
Full audit log
Role-based access
Zero-knowledge credentials
Encryption

Credentials encrypted before they leave your browser

Lexful uses client-side encryption for the credential vault. Credential values are encrypted with your account's unique key before transmission. The server stores ciphertext, not plaintext.

  • AES-256-GCM encryption for every credential value
  • Encryption keys never leave the client
  • Server-side searches operate on encrypted indexes
  • TLS 1.3 for all API communication
  • HSTS preloading on all endpoints
Abstract encryption and data security concept
Vault Access

No credential is visible without a reason

Every credential reveal in Lexful requires an active session and a recorded reason. Techs can't browse credentials without a ticket context. Managers can see every reveal event, who triggered it, and when.

  • Credentials masked by default until explicitly revealed
  • Reveal triggers a timestamped access log entry
  • Log includes user, client environment, and linked ticket
  • Anomalous access patterns trigger manager alert email
  • Log export available for compliance audits
Credential Access Log Last 30 days
Fortigate Admin
Hartwell Construction
J. Okonkwo
2026-08-03 02:14
Exchange Admin
Meridian Medical Group
S. Patel
2026-08-01 14:52
Backup passphrase
Cascade Logistics
T. MacPherson
2026-07-29 09:07
Access Control

Role-based permissions built for MSP team structure

Lexful's permission model maps to how MSPs actually work. Admins control client onboarding and team access. Techs access only the clients they're assigned. Read-only viewer roles are available for client escalation paths.

  • Three roles: Admin, Technician, Viewer
  • Per-client environment assignment for technicians
  • Credential reveal requires Technician role or higher
  • Viewers see runbooks and assets, never credentials
  • MFA enforced for Admin and Technician roles
Permission Admin Tech Viewer
View runbooks
Edit runbooks
Reveal credentials
Manage team members
Export credential log
Audit and Compliance

The paper trail your clients' compliance auditors expect

Tamper-evident log

Every write, read, and delete event produces a signed log entry. Log entries cannot be edited or deleted. Exportable in CSV and JSON for compliance review.

Full version history

Runbooks and asset records keep a complete version history. Roll back any document to any prior state. Compare diffs between versions without losing current work.

Security controls documentation

We're building toward SOC 2 Type II certification. MSP plan subscribers receive our current security controls documentation for use in client security questionnaires and vendor reviews while that process is underway.

What's Coming

Security roadmap

We publish our near-term security roadmap so customers know what controls are coming. Current work in progress:

  • In progress Hardware security key (FIDO2) support for MFA
  • In progress Vault key rotation without service interruption
  • Planned IP allowlist for Admin role actions
  • Planned SIEM log push (Splunk, Sentinel) for MSP plan
  • Planned Client-controlled encryption key option
Infrastructure

Built on durable foundations

Lexful runs on AWS infrastructure with multi-region replication. Data does not leave US-based regions unless you configure a non-US account zone.

  • Live AWS us-east-1 primary, us-west-2 standby
  • Live Daily encrypted backups with 30-day retention
  • Live 99.9% uptime SLA for MSP plan
  • Live DDoS protection on all public endpoints
  • In progress EU data residency zone