Building trust through transparency.
The single place to understand how CreateLixir approaches security, privacy, reliability, responsible AI, and product transparency — with every claim traceable to the surface that owns the detail.
An aggregator — not a legal policy, not the security page itself
One place. Five commitments. Everything traceable.
The Trust Center is the public hub for how CreateLixir approaches everything a customer needs to trust us on — security, privacy, platform reliability, responsible AI, and product transparency.
It doesn't duplicate the pages that own each of these areas. It aggregates them, gives you a fast route to the right place, and grows over time as we publish new artefacts: compliance reports, whitepapers, incident history, and responsible-disclosure programs.
Five commitments, one hub.
Each pillar has its own dedicated surface. Follow the link to go deep — or read the summaries below for the short version.
- PillarSecurity
Encryption, isolation, and least privilege by default.
- PillarPrivacy
Your data is scoped to your workspace, and it's yours to keep.
- PillarReliability
Stable infrastructure, continuous monitoring, honest updates.
- PillarResponsible AI
Humans in the loop, grounded reasoning, no training on your data.
- PillarTransparency
Release Notes, Changelog, and Roadmap — always current.
Encryption, isolation, and least privilege by default.
Security is a continuous discipline for us — not a checkbox. The full picture, with every claim labelled Shipped or Planned, lives on the Security page.
Every workspace is encrypted in transit and at rest, scoped to its own tenant boundary, and protected by an envelope-encrypted secrets vault that keeps credentials out of AI prompts by design. Authentication uses Better Auth with modern defaults, and two-factor plus SSO ship alongside Enterprise workspaces.
Your data is yours — scoped, protected, portable.
Privacy is an essential part of how we build the platform, not a policy tacked on at the end. The Privacy page is the source of truth for how we handle personal information.
We collect only what CreateLixir needs to run the features you're using. Your prompts, files, and generated code stay inside your workspace and are never used to train AI models — ours or third-party. You can access, export, and delete your data at any time.
Where you'll check whether the platform is up.
A dedicated live status page ships alongside the broader observability work. Until then, incidents that meaningfully affect users are communicated in the Changelog and directly to customers.
Live status page
PlannedRealtime uptime and incident history for every user-facing service. It will surface here first when it lands.
Capable AI, responsibly deployed.
AI-powered software creation touches sensitive project information constantly. The principles below are how we treat that responsibility.
The single most consequential decision we made is keeping secrets out of prompts. Everything else — grounding, human oversight, transparency — follows from taking that seriously and applying the same discipline everywhere else the AI reaches.
- Human oversight
Every meaningful AI decision lands on a human's screen with reasoning attached. AI takes the leverage, humans keep the intent.
- Transparency
The reasoning behind AI output is traceable back to project source. No black-box confidence.
- Reliability
Grounded, retrieval-driven responses over confident guessing. The platform prefers accurate to impressive.
- Safety
Secrets never enter AI prompts by design. High-risk actions require explicit human approval.
- Continuous improvement
AI safety is an operational practice, not a milestone. We refine controls as the platform evolves.
Boring is a compliment.
Users don't want thrilling infrastructure. They want the platform to be there tomorrow, and Wednesday, and next February. That's the bar we hold ourselves to.
We don't publish uptime numbers here because we prefer to invest that engineering time in the systems that make them good — and to communicate incidents honestly when they happen. A live status page is on the roadmap.
- Stable infrastructure
We build on managed cloud providers with strong reliability postures and layer our own controls on top.
- Performance
Latency is treated as a design decision. Every surface has a performance budget from the moment it's sketched.
- Continuous monitoring
Application logs, error tracking, and infrastructure observability are baseline — not phase two.
- Ongoing improvements
We invest ahead of pain — instrumenting the parts of the platform users depend on before they become the parts users complain about.
The controls behind everything above.
A high-level view of what protects the data you trust us with. The Security page carries the full detail, with every claim explicitly labelled as shipped or planned.
Secure authentication
Modern password hashing, OAuth via major identity providers, and hardened session defaults.
Access controls
Every workspace has explicit members, roles, and permissions — revocable at any time.
Encryption
Data encrypted in transit and at rest. Integration credentials protected by envelope encryption.
Infrastructure security
Managed cloud infrastructure with proven security postures — plus our own controls layered on top.
Account protection
Rate-limited recovery flows, session review, and — soon — two-factor authentication.
Privacy by design
We retain only what CreateLixir needs to run the features you use. Your project data stays yours.
You should always be able to see what we shipped.
Product evolution is visible by default. Every meaningful change lands in these three surfaces so you never have to guess what's new.
The Release Notes tell the story. The Changelog records every entry. The Roadmap shows what's next. Together they close the loop between what we say we'll do and what we actually do — publicly.
The Trust Center will grow with the platform.
These artefacts aren't here yet — but they're planned. We'll add each one when the underlying practice is mature enough to publish honestly.
Trust hubs at larger companies bristle with compliance reports, whitepapers, disclosure programs, and years of incident history. We're building toward the same shape — without publishing anything before it's real.
- Compliance informationPlanned
SOC 2 and ISO 27001 attestation reports as we complete audits.
- Audit reportsPlanned
Summaries of independent security assessments and penetration tests.
- Security whitepapersPlanned
Deeper technical writing on how specific platform controls work.
- Vulnerability disclosurePlanned
Responsible disclosure program with clear scope and acknowledgements.
- Incident historyPlanned
Public record of significant incidents with root cause and remediation.
- Trust documentationPlanned
DPAs, subprocessor lists, and other artefacts organisations expect from serious platforms.
Trust Center questions people actually ask.
The single public destination for everything related to CreateLixir's approach to trust — security, privacy, reliability, responsible AI, and transparency. It's an aggregator: every section links out to the surface that owns the detail.
Where else to look.
Trust is a system of interlocking pages. These are the ones this hub points to.
Transparency. Reliability.
Continuous improvement.
This Trust Center will keep growing as CreateLixir does. Every artefact we add reflects a practice that's mature enough to publish — not one we're aspiring to.