LSAS Platform

Govern what AI can say, do, and decide — at runtime.

Privacy and data handling

Last updated:

LSAS Platform operates this website and its evaluation sandbox. This page describes the application data flows visible in the implementation. Agreements for a particular customer deployment may impose additional requirements; the website notice and terms remain subject to legal review.

Data handling varies by surface. Review the actual provider, connector, retention, and hosting configuration before supplying sensitive information.

Website and contact information

  • The contact form accepts your name, work email, company, optional role, phone and timeline, and your message. Submitted details are stored for responding to LSAS Platform inquiries.
  • When configured, the email delivery service receives contact details to send the inquiry and a confirmation. Hosting and database service providers process information required to operate the site.
  • Public download and search measurement is opt-in in the browser and uses allowlisted event topics. Raw search text is not accepted as an analytics topic. The application does not load the former global third-party analytics script.

Accounts and administrative activity

  • Account records include identity and membership information, password hashes, sessions, and invitations. Session cookies support sign-in and access control.
  • Protected changes produce audit records with relevant actor, tenant, version, and action context. These records can contain personal identifiers needed for accountability.
  • Tenant-scoped access and assigned review roles restrict application access. Platform administration has separate privileges; a tenant boundary is not a promise that infrastructure operators cannot access stored data.

Runtime and assessment content

  • Model decision telemetry normally records derived findings and outcomes. Run Engine inputs, evidence, reports, workflow artifacts, and connector records can include supplied content.
  • The output-review profile stores the exact held artifact in encrypted form for authorized inspection and release. Encryption does not make that artifact anonymous.
  • Pattern redaction is limited to the implemented checks and transformations. It does not guarantee removal of all personal information from every stored field or log.

Providers and deployment boundaries

  • A model or connector request transmits the permitted payload to its configured destination. The destination provider has its own processing and retention terms.
  • The public site is a hosted evaluation service. Customer-hosted, private-cloud, and on-premise arrangements require deployment work and verification; they are not automatically provisioned by this application.
  • Residency, backup storage, network access, TLS, encryption at rest, and service-provider agreements depend on the hosting configuration. This code review does not establish those external controls.

Retention and requests

  • Configured retention policies and legal holds govern supported worker cleanup. Running the worker is required; a saved setting alone does not delete records.
  • Database backups, infrastructure logs, external provider records, and contact records have separate lifecycles that must be included in the operator’s retention policy.
  • Contact LSAS Platform through the contact page for questions about information submitted to this site or requests relating to it. Applicable obligations and customer instructions require case-specific review.

Public sandbox

  • Use synthetic or approved public sandbox data. The Epic demonstration uses dedicated sandbox patient read/search flows and intentionally shows baseline and governed results.
  • Published homepage counts are aggregate activity for an explicitly configured demo application. Simulated override activity is separate from authoritative protected approvals.
  • Demo content may be throttled, reset, retained for evaluation, or removed. Do not use the public sandbox to submit real patient data, payment credentials, private keys, or confidential production content.