Skip to main content
    Security & Compliance

    Your data, protected by design

    Security isn't an afterthought at LiveFox. From encryption standards to access controls, every layer of our platform is built to keep your organisation's data safe and compliant.

    Encryption Standards

    TLS 1.3 In Transit

    All data transmitted between your browser and our servers is encrypted using TLS 1.3, the latest and most secure transport layer protocol.

    AES-256 At Rest

    All stored data — including quiz content, user profiles, and analytics — is encrypted at rest with AES-256, the gold standard for symmetric encryption.

    Key Management

    Encryption keys are managed through industry-standard key management services with automatic rotation and strict access controls.

    GDPR Compliance

    LiveFox is fully committed to the EU General Data Protection Regulation. We act as a data processor on behalf of your organisation and uphold every data subject right.

    Right to Data Portability

    Export all your personal data at any time as a structured JSON file from your Profile Settings page.

    Right to Erasure

    Request complete deletion of your account and all associated data. Our deletion process purges data across every table in our system.

    Right to Access

    View exactly what personal data we hold about you, including quiz history, answers, IP logs, and activity records.

    Lawful Basis & Consent

    We process data based on legitimate interest and explicit consent. You can withdraw consent at any time without affecting prior processing.

    Data Processing Agreement (DPA) — Our standard GDPR-compliant DPA (v1.2) is available to read or download at /dpa. A countersigned copy can be requested from support@golivefox.com.

    SOC 2 Aligned Controls

    Our security controls are aligned with the SOC 2 Trust Services Criteria. We are actively working towards formal SOC 2 Type II certification.

    Access Controls

    Role-based access control (RBAC) enforced at the database level via Row-Level Security policies. Every query is scoped to the authenticated user's organisation.

    Audit Logging

    All significant actions — logins, data changes, permission updates — are recorded with timestamps, IP addresses, and user-agent strings in immutable audit logs.

    Incident Response

    Documented incident response procedures with defined escalation paths. Infrastructure monitoring with automated alerting for anomalous activity.

    Change Management

    All infrastructure and code changes go through version-controlled deployments with review processes and rollback capabilities.

    Infrastructure Security

    Cloud Infrastructure

    Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certified providers. High-availability database with point-in-time recovery and daily backups.

    Network Security

    Web Application Firewall (WAF), DDoS protection, and rate limiting protect against common attack vectors. All endpoints enforce HTTPS.

    Vulnerability Management

    Regular dependency scanning and security audits. Critical vulnerabilities are patched within 24 hours of disclosure.

    Data Isolation

    Strict tenant isolation at the database level. Organisation data is logically separated and access is enforced through server-side policies.

    Data Residency

    Customer data is hosted in the European Union by default. We use AWS Frankfurt (eu-central-1) via our managed database provider, and EU/UK customer data does not leave the EU/EEA for primary storage or backups.

    EU customers (default): All session, quiz and account data is stored in the EU. Sub-processors handling data in the US (email, AI inference) operate under EU Standard Contractual Clauses (2021) and the UK IDTA where applicable.

    US data residency: A dedicated US-hosted deployment is available as an enterprise add-on, with all customer data stored exclusively in US regions. Contact us for pricing and provisioning.

    Full sub-processor list with hosting regions: /subprocessors.

    Breach Notification

    In the event of a confirmed personal-data breach affecting customer data, we will notify affected organisation account owners by email within 72 hours of confirmation, in line with GDPR Article 33. Notifications include the nature of the breach, data categories affected, our mitigation steps, and recommended actions for the customer. Where required, we also notify the relevant supervisory authority.

    Responsible Disclosure

    If you believe you've found a security vulnerability in LiveFox, please email support@golivefox.com with details. We will acknowledge your report within 48 hours and keep you updated as we investigate.

    Safe harbour: we will not pursue legal action against good-faith security researchers who: (1) report promptly, (2) avoid privacy violations, data destruction or service disruption, (3) do not access more data than necessary to demonstrate the issue, and (4) give us reasonable time to remediate before public disclosure.

    Last updated: May 2026