A plain-language summary — the full text below is what legally applies.
1.1Security is foundational to everything Lacspace builds. We apply defence-in-depth across our platforms and continuously improve our controls. This page describes how we protect your data and how security researchers can report issues to us responsibly.
Tenant isolation — every record carries a tenant; every query filters by it, so customers' data is separated by design.
Encryption — data is encrypted in transit; sensitive data is protected at rest.
Access control — least-privilege, role-based access with authentication and session management.
Audit logging — append-only logs record who did what, when, and where.
Monitoring — we monitor for anomalies and respond to incidents.
3.1We process personal data in line with our Privacy Policy, apply data-minimisation, and support consent and deletion. For regulated data (such as health records), we apply heightened safeguards and honour applicable retention and localisation obligations.
4.1We welcome reports from security researchers. If you believe you have found a vulnerability in a Lacspace Service, please report it privately and give us reasonable time to fix it before any public disclosure. Please act in good faith, avoid privacy violations and service disruption, and never access or modify data that is not yours.
5.1In scope are Lacspace-owned production Services and domains. Please avoid testing that could harm users or data — no denial-of-service, spam, social engineering of our staff or customers, or physical attacks. If you are unsure whether something is in scope, ask us first.
6.1If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorised, will not pursue legal action against you for that research, and will work with you to understand and resolve the issue quickly. This safe harbor does not apply to actions that harm users, breach privacy, or violate the law.
Reports from automated scanners without a demonstrated, exploitable impact.
Missing best-practice headers or configurations with no real security impact.
Social engineering, physical access, or attacks requiring a compromised device.
Denial-of-service, rate-limit, or volumetric issues.
8.1Email security@lacspace.com with:
a clear description of the issue and the affected Service or URL;
steps to reproduce, proof-of-concept, and potential impact;
your contact details so we can follow up.
9.1We aim to acknowledge reports promptly, validate and triage them, keep you updated on remediation, and confirm when a fix is deployed. Timelines depend on severity and complexity, and we appreciate your patience and coordination on disclosure timing.
10.1We are grateful to researchers who help keep our users safe. With your permission, we are happy to acknowledge valid, first-report contributions. Any reward is at our discretion and depends on impact and report quality.
11.1Reach our security team at security@lacspace.com. For privacy matters, contact privacy@lacspace.com.
This document is version v1.0, effective 25 July 2026 (updated 25 July 2026), comprising 11 sections and 21 clauses. Published by Lacspace Corporation Pvt. Ltd. — a global, country-neutral technology company registered in India (CIN U46511DL2025PTC079972) and Nepal (Reg. No. 377566/82/83). © 2026 Lacspace Corporation Pvt. Ltd. All rights reserved.
Download a watermarked copy: security.pdf. The authoritative version is always the one published on this page.
Privacy PolicyData Processing AgreementAcceptable Use PolicySub-processors