CreateLixir
Trust Center

Building trust through transparency.

The single place to understand how CreateLixir approaches security, privacy, reliability, responsible AI, and product transparency — with every claim traceable to the surface that owns the detail.

An aggregator — not a legal policy, not the security page itself

Five pillars
Trust
What is the Trust Center?

One place. Five commitments. Everything traceable.

The Trust Center is the public hub for how CreateLixir approaches everything a customer needs to trust us on — security, privacy, platform reliability, responsible AI, and product transparency.

It doesn't duplicate the pages that own each of these areas. It aggregates them, gives you a fast route to the right place, and grows over time as we publish new artefacts: compliance reports, whitepapers, incident history, and responsible-disclosure programs.

Trust isn't a certificate on a wall. It's a pattern of doing what we said we would do — repeatedly, quietly, and in public.
Security

Encryption, isolation, and least privilege by default.

Security is a continuous discipline for us — not a checkbox. The full picture, with every claim labelled Shipped or Planned, lives on the Security page.

Every workspace is encrypted in transit and at rest, scoped to its own tenant boundary, and protected by an envelope-encrypted secrets vault that keeps credentials out of AI prompts by design. Authentication uses Better Auth with modern defaults, and two-factor plus SSO ship alongside Enterprise workspaces.

Privacy

Your data is yours — scoped, protected, portable.

Privacy is an essential part of how we build the platform, not a policy tacked on at the end. The Privacy page is the source of truth for how we handle personal information.

We collect only what CreateLixir needs to run the features you're using. Your prompts, files, and generated code stay inside your workspace and are never used to train AI models — ours or third-party. You can access, export, and delete your data at any time.

Platform status

Where you'll check whether the platform is up.

A dedicated live status page ships alongside the broader observability work. Until then, incidents that meaningfully affect users are communicated in the Changelog and directly to customers.

Live status page

Planned

Realtime uptime and incident history for every user-facing service. It will surface here first when it lands.

View Changelog
Responsible AI

Capable AI, responsibly deployed.

AI-powered software creation touches sensitive project information constantly. The principles below are how we treat that responsibility.

The single most consequential decision we made is keeping secrets out of prompts. Everything else — grounding, human oversight, transparency — follows from taking that seriously and applying the same discipline everywhere else the AI reaches.

  • Human oversight

    Every meaningful AI decision lands on a human's screen with reasoning attached. AI takes the leverage, humans keep the intent.

  • Transparency

    The reasoning behind AI output is traceable back to project source. No black-box confidence.

  • Reliability

    Grounded, retrieval-driven responses over confident guessing. The platform prefers accurate to impressive.

  • Safety

    Secrets never enter AI prompts by design. High-risk actions require explicit human approval.

  • Continuous improvement

    AI safety is an operational practice, not a milestone. We refine controls as the platform evolves.

Reliability

Boring is a compliment.

Users don't want thrilling infrastructure. They want the platform to be there tomorrow, and Wednesday, and next February. That's the bar we hold ourselves to.

We don't publish uptime numbers here because we prefer to invest that engineering time in the systems that make them good — and to communicate incidents honestly when they happen. A live status page is on the roadmap.

  • Stable infrastructure

    We build on managed cloud providers with strong reliability postures and layer our own controls on top.

  • Performance

    Latency is treated as a design decision. Every surface has a performance budget from the moment it's sketched.

  • Continuous monitoring

    Application logs, error tracking, and infrastructure observability are baseline — not phase two.

  • Ongoing improvements

    We invest ahead of pain — instrumenting the parts of the platform users depend on before they become the parts users complain about.

Data protection

The controls behind everything above.

A high-level view of what protects the data you trust us with. The Security page carries the full detail, with every claim explicitly labelled as shipped or planned.

  • Secure authentication

    Modern password hashing, OAuth via major identity providers, and hardened session defaults.

  • Access controls

    Every workspace has explicit members, roles, and permissions — revocable at any time.

  • Encryption

    Data encrypted in transit and at rest. Integration credentials protected by envelope encryption.

  • Infrastructure security

    Managed cloud infrastructure with proven security postures — plus our own controls layered on top.

  • Account protection

    Rate-limited recovery flows, session review, and — soon — two-factor authentication.

  • Privacy by design

    We retain only what CreateLixir needs to run the features you use. Your project data stays yours.

Transparency

You should always be able to see what we shipped.

Product evolution is visible by default. Every meaningful change lands in these three surfaces so you never have to guess what's new.

The Release Notes tell the story. The Changelog records every entry. The Roadmap shows what's next. Together they close the loop between what we say we'll do and what we actually do — publicly.

Looking ahead

The Trust Center will grow with the platform.

These artefacts aren't here yet — but they're planned. We'll add each one when the underlying practice is mature enough to publish honestly.

Trust hubs at larger companies bristle with compliance reports, whitepapers, disclosure programs, and years of incident history. We're building toward the same shape — without publishing anything before it's real.

  • Compliance information
    Planned

    SOC 2 and ISO 27001 attestation reports as we complete audits.

  • Audit reports
    Planned

    Summaries of independent security assessments and penetration tests.

  • Security whitepapers
    Planned

    Deeper technical writing on how specific platform controls work.

  • Vulnerability disclosure
    Planned

    Responsible disclosure program with clear scope and acknowledgements.

  • Incident history
    Planned

    Public record of significant incidents with root cause and remediation.

  • Trust documentation
    Planned

    DPAs, subprocessor lists, and other artefacts organisations expect from serious platforms.

FAQ

Trust Center questions people actually ask.

  • The single public destination for everything related to CreateLixir's approach to trust — security, privacy, reliability, responsible AI, and transparency. It's an aggregator: every section links out to the surface that owns the detail.

Trust, earned over time

Transparency. Reliability.
Continuous improvement.

This Trust Center will keep growing as CreateLixir does. Every artefact we add reflects a practice that's mature enough to publish — not one we're aspiring to.