> For the complete documentation index, see [llms.txt](https://support.limy.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.limy.ai/trust-center.md).

# Trust Center

This page explains how Limy protects customer data, manages security, and supports customer privacy and compliance requirements.

## Security and privacy at Limy

Limy primarily processes

* **Customer business and analytics data**: Brand-performance metrics, AI-search visibility data, website analytics, content, product, marketing, and related information provided by customers.
* **Public AI-search data:** Publicly available AI-generated search results and LLM recommendation outputs that Limy monitors for customers.

Limy also processes limited personal data needed to operate the service, including user account and authentication information and technical identifiers.

{% hint style="warning" %}
If a customer implements Limy's CDN integration or GTM pixel, Limy may process IP addresses as a data processor on the customer's behalf.
{% endhint %}

{% hint style="info" %}
Limy does not process special categories of personal data as part of its standard services. More information is available in Limy's Data Processing Agreement.
{% endhint %}

## Security controls

#### Encryption

{% hint style="info" icon="lock" %}
Customer data is encrypted in transit using TLS 1.2 and is encrypted at rest using industry-standard encryption.
{% endhint %}

#### Access controls

Limy uses role-based access control and the principle of least privilege. Access to customer data is limited to authorized personnel who require it for their work.

{% hint style="info" icon="key" %}
Limy requires multi-factor authentication for systems that provide access to customer data, including production infrastructure, source-code repositories, and build tools.
{% endhint %}

#### Personnel security

All employees receive annual security-awareness training. Confidentiality obligations are included in employment agreements.

#### Monitoring and incident response

Limy maintains security-monitoring and incident-response procedures. Under the Data Processing Agreement, Limy notifies affected customers without undue delay and no later than 48 hours after becoming aware of a confirmed security incident involving customer data in Limy's possession or control.

{% hint style="success" icon="shield-check" %}
No security incidents were identified during the SOC 2 audit period from December 1, 2025 through February 28, 2026.
{% endhint %}

## Compliance

#### SOC 2 Type II

Limy completed a SOC 2 Type II examination for the period from December 1, 2025 through February 28, 2026. The examination covered controls relevant to Security, Availability, and Confidentiality.

{% hint style="success" icon="badge-check" %}
The examination was performed by Kost Forer Gabbay and Kasierer, a member firm of Ernst & Young Global Limited. The auditor concluded that the covered controls were suitably designed and operated effectively during the audit period.
{% endhint %}

#### GDPR and international data transfers

Limy maintains a GDPR compliance program and offers a Data Processing Agreement that includes Technical and Organizational Measures.

{% hint style="info" icon="globe" %}
The European Commission recognizes Israel as providing an adequate level of protection for covered personal-data transfers. Limy's Data Processing Agreement also includes Standard Contractual Clauses for applicable transfers to countries that are not recognized as providing an adequate level of protection.
{% endhint %}

## Business continuity and recovery

{% hint style="success" %}
Limy maintains business-continuity and disaster-recovery procedures.
{% endhint %}

| Metric                             | Commitment                                                                |
| ---------------------------------- | ------------------------------------------------------------------------- |
| **Recovery Time Objective (RTO)**  | 12 hours                                                                  |
| **Recovery Point Objective (RPO)** | 24 hours                                                                  |
| **Monthly uptime commitment**      | 99.5%, subject to the terms and exclusions in the Service Level Agreement |

## Penetration testing and vulnerability management

Limy conducts penetration testing at least annually. High-severity findings are investigated and remediated through Limy's software-development lifecycle or other appropriate measures.

Limy also performs continuous vulnerability assessments across its production environment, infrastructure, and network. Vulnerability scanning is integrated into the software-development process.

## Infrastructure and service providers

{% hint style="info" %}
Limy relies on a small number of vetted sub-processors for cloud infrastructure, analytics storage, and authentication. The full list, along with their roles and locations, is documented in Limy's Data Processing Agreement, available upon request.
{% endhint %}

## Documents

#### Legal and privacy

* [Privacy Policy](https://www.limy.ai/legal/privacy-policy)
* [Cookie Policy](https://www.limy.ai/legal/cookie-policy)
* [Terms and Conditions](https://www.limy.ai/legal/terms-and-conditions)
* Data Processing Agreement: Available upon request

#### Security and compliance

* SOC 2 Type II Report, December 2025 through February 2026: Available upon request (add email)
* Penetration-testing materials: Executive summary and remediation report available upon request

#### Service and reliability

* Service Level Agreement: Available upon request

## Frequently asked questions

<details>

<summary><strong>Does Limy process personally identifiable information?</strong></summary>

Limy primarily processes customer business and analytics data and publicly available AI-search data. Limy also processes limited personal data needed to operate the service, including user account and authentication information and technical identifiers.

If a customer implements Limy's CDN integration or GTM pixel, Limy may process IP addresses as a data processor on your behalf.

</details>

<details>

<summary><strong>Is customer data encrypted?</strong></summary>

Yes. Customer data is encrypted in transit using TLS 1.2 and is encrypted at rest using industry-standard encryption.

</details>

<details>

<summary><strong>Does Limy require multi-factor authentication?</strong></summary>

Yes. Limy requires multi-factor authentication for systems that provide access to customer data, including production infrastructure, source-code repositories, and build tools.

</details>

<details>

<summary><strong>Has Limy completed a SOC 2 examination?</strong></summary>

Yes. Limy completed a SOC 2 Type II examination covering Security, Availability, and Confidentiality for the period from December 1, 2025 through February 28, 2026.

</details>

<details>

<summary><strong>Has Limy experienced any security incidents?</strong></summary>

No security incidents were identified during the SOC 2 audit period from December 1, 2025 through February 28, 2026.

</details>

<details>

<summary><strong>Does Limy conduct penetration testing?</strong></summary>

Yes. Limy conducts penetration testing at least annually. An executive summary and remediation report are available upon request.

</details>

<details>

<summary><strong>What are Limy's recovery objectives?</strong></summary>

Limy's Recovery Time Objective is 12 hours. Its Recovery Point Objective is 24 hours.

</details>

<details>

<summary><strong>How does Limy support GDPR requirements?</strong></summary>

Limy maintains a GDPR compliance program and offers a Data Processing Agreement with Technical and Organizational Measures and Standard Contractual Clauses for applicable international transfers.

</details>

<details>

<summary><strong>What access controls does Limy use?</strong></summary>

Limy uses role-based access control, the principle of least privilege, and multi-factor authentication to restrict access to systems and customer data.

</details>
