Designed to protect the access that protects your clients
Every credential in Lexful is encrypted at rest and in transit. Every access is logged. Your MSP's knowledge base should never become its weakest link.
Credentials encrypted before they leave your browser
Lexful uses client-side encryption for the credential vault. Credential values are encrypted with your account's unique key before transmission. The server stores ciphertext, not plaintext.
- AES-256-GCM encryption for every credential value
- Encryption keys never leave the client
- Server-side searches operate on encrypted indexes
- TLS 1.3 for all API communication
- HSTS preloading on all endpoints
No credential is visible without a reason
Every credential reveal in Lexful requires an active session and a recorded reason. Techs can't browse credentials without a ticket context. Managers can see every reveal event, who triggered it, and when.
- Credentials masked by default until explicitly revealed
- Reveal triggers a timestamped access log entry
- Log includes user, client environment, and linked ticket
- Anomalous access patterns trigger manager alert email
- Log export available for compliance audits
Role-based permissions built for MSP team structure
Lexful's permission model maps to how MSPs actually work. Admins control client onboarding and team access. Techs access only the clients they're assigned. Read-only viewer roles are available for client escalation paths.
- Three roles: Admin, Technician, Viewer
- Per-client environment assignment for technicians
- Credential reveal requires Technician role or higher
- Viewers see runbooks and assets, never credentials
- MFA enforced for Admin and Technician roles
The paper trail your clients' compliance auditors expect
Tamper-evident log
Every write, read, and delete event produces a signed log entry. Log entries cannot be edited or deleted. Exportable in CSV and JSON for compliance review.
Full version history
Runbooks and asset records keep a complete version history. Roll back any document to any prior state. Compare diffs between versions without losing current work.
Security controls documentation
We're building toward SOC 2 Type II certification. MSP plan subscribers receive our current security controls documentation for use in client security questionnaires and vendor reviews while that process is underway.
Security roadmap
We publish our near-term security roadmap so customers know what controls are coming. Current work in progress:
- In progress Hardware security key (FIDO2) support for MFA
- In progress Vault key rotation without service interruption
- Planned IP allowlist for Admin role actions
- Planned SIEM log push (Splunk, Sentinel) for MSP plan
- Planned Client-controlled encryption key option
Built on durable foundations
Lexful runs on AWS infrastructure with multi-region replication. Data does not leave US-based regions unless you configure a non-US account zone.
- Live AWS us-east-1 primary, us-west-2 standby
- Live Daily encrypted backups with 30-day retention
- Live 99.9% uptime SLA for MSP plan
- Live DDoS protection on all public endpoints
- In progress EU data residency zone