Security

Security overview

Last updated 14 June 2026Governing law: England & WalesController: LaunchLane Limited (in formation), England & Wales

Security is a product feature. Here's how we protect your workspace and how to report something if it looks wrong.

Encryption

  • TLS 1.2+ for all traffic between your browser and LaunchLane.
  • AES-256 encryption at rest for databases, file storage and backups.
  • Secrets stored in a managed vault with strict access policies.

Access controls

  • Row-level security on every customer-facing table — your workspace is isolated by design.
  • Principle of least privilege for staff; production access is gated, logged and auditable.
  • SSO + 2FA enforced for all LaunchLane personnel.

Hosting and resilience

  • Primary data hosted in the UK/EU on tier-1 cloud infrastructure.
  • Automated daily backups, point-in-time recovery, 90-day rotation.
  • Edge-cached delivery with DDoS protection and WAF.

Application security

  • Dependency scanning and SAST in CI; security review for sensitive changes.
  • Server-side input validation and CSRF protection on state-changing endpoints.
  • Privileged actions require an authenticated session and an explicit role check.

Monitoring and incidents

We monitor application and infrastructure logs, alert on anomalies, and rehearse incident response. Personal data breaches are notified to affected customers without undue delay and within 72 hours of awareness.

Responsible disclosure

Found a vulnerability? Please report it to security@launchlane.uk. We commit to:

  • Acknowledge your report within 2 business days.
  • Triage and update you on progress.
  • Not pursue legal action for good-faith research that follows this policy.

Please don't access data that isn't yours, disrupt the Service, or publicly disclose before we've had a reasonable chance to fix the issue.