Security

Security and privacy

Your work is the most sensitive data you have. Here is precisely how Lodestar holds it.

Encrypted per user

Data is encrypted at rest with envelope encryption: each user has their own data key, wrapped by a master key. Your workspace is cryptographically separated from everyone else's rather than sharing one key with the whole system.

We do not train on your data

Your mail, files, messages and documents are never used to train models — ours or anyone else's. They are used to answer your questions and run the jobs you asked for, and nothing else.

Least privilege on every connection

Lodestar requests only the OAuth scopes a feature needs, and each integration can be turned off independently. Teams channel access is the clearest example: it would require tenant-wide admin consent, so we do not ask for it. Disconnecting an account stops all future syncing.

Writes are gated, not assumed

Sending mail, creating events and calling an external tool sit behind explicit confirmation. Chat has a plan mode that blocks writes outright, so you can think out loud without anything acting on it.

Roles and an audit trail

Workspaces have owners, editors and viewers, and each one keeps its own audit log of membership and administrative changes. Viewers see what they are entitled to see and nothing more.

Export and erasure

You can export your data and you can delete your account. Deletion removes the derived material too, including the indexed passages used for retrieval — not just the rows you can see.

  • ·Envelope encryption with a per-user data key
  • ·Never used for model training
  • ·Minimum OAuth scopes, per-integration switches
  • ·Confirmation before sends and external tool calls
  • ·Owner, editor and viewer roles with an audit trail
  • ·Full export and account erasure