Security at Code Lexica
Your code and your usage data are your most sensitive assets. We protect both with enterprise-grade security practices: SOC 2 Type 1 certified, aligned with NIST 800-53 Rev 5, and Track never touches your source code at all.
What we collect, by product
Data handling differs by product. Track collects usage metadata only; our code-intelligence products index the repositories you choose to connect.
Track — usage metadata only
The Track CLI reads the local usage logs your AI coding tools already write and sends usage metadata: token counts, model names, costs, session metadata, repo and branch names, and commit stats. It never sends file contents, never source code, and never your prompts or responses.
Code intelligence — indexed with protection
Optimize (Premium) and our reports products index the repositories you choose to connect, as a separate, explicit step. Code is encrypted in transit and at rest, isolated per organization, used only to power your analysis and context, and never used to train AI models.
Compliance & Certifications
We're committed to earning and maintaining the certifications that matter to enterprise teams.
NIST 800-53 Rev 5
Our security program is engineered to align with the NIST 800-53 Rev 5 framework across all control families.
SOC 2 Type 1
Certified. An independent audit validated that our security controls are properly designed and implemented.
SOC 2 Type 2
Scheduled to follow our Type 1 certification. Validates the ongoing operating effectiveness of our controls.
Defense in Depth
Our security program covers six key domains, each mapped to SOC 2 Trust Criteria and NIST controls.
Governance & Control
Dedicated CISO leadership, formal risk management strategy, personnel screening, NDAs for all employees and contractors, and continuous security awareness training.
Secure Development
Security integrated into every phase of our SDLC. All code changes require peer review via pull requests, with static and dynamic code analysis to catch vulnerabilities before they reach production.
Identity & Access
Role-based access control (RBAC) enforcing least privilege across all systems. Multi-factor authentication required for all cloud services and privileged accounts, with replay-resistant session mechanisms.
Vulnerability Management
Periodic vulnerability scanning, dependency health mapping to identify outdated packages, and continuous attack surface reduction by restricting unnecessary functions, ports, and protocols.
Operational Resilience
Formal incident response plan covering preparation through recovery. Automated system monitoring with near real-time alerts, encryption at rest, and geographically distributed encrypted backups.
Audit & Accountability
Automated audit record generation for all security-relevant events. Regular log review and analysis to identify inappropriate or unusual activity supporting forensic investigations.
Enterprise Security
Advanced security features for organizations with elevated requirements.
Isolated Cloud Hosting
Dedicated infrastructure for your organization
Self-Hosted
Deploy within your own environment
Bring Your Own Key
Your API keys stay yours; model traffic runs under your own provider account
Enterprise security features may be available depending on your requirements. To learn more or to request access to our security data room, reach out to support@codelexica.com.
Security FAQ
Policies & Resources
Review our legal and privacy commitments.
Have Security Questions?
Our team is happy to discuss your security requirements, walk through our controls, or provide access to our security data room.