Trust & Security
Last updated: June 17, 2026
This page is maintained by the LiveGBX team to answer common security and privacy questions about LiveGBX. It describes practices and controls that are enabled in the product today. It is editable project content, not an independent certification or third-party audit.
Shared responsibility
LiveGBX runs on a managed cloud platform. We rely on the platform for secure hosting, database isolation, and key management. We are responsible for application logic, access policies, and the product features described below. You are responsible for your account credentials, the data you put into your workspace, and the teammates you invite.
Access & authentication
- Email/password and Google sign-in.
- Passkey (WebAuthn) support for passwordless sign-in.
- Optional MFA gate for workflows handling sensitive health information.
- Session bindings and device sign-out controls.
- Rate limiting on authentication attempts.
Authorization
- Multi-tenant isolation by organization and venture.
- Row-level security policies enforced in the database — users only see data for organizations and ventures they belong to.
- Role-based access (owner, admin, team lead, member) with section-level permissions configurable per venture.
- Sensitive case data (workflow cases, case members, case artifacts) is restricted to direct venture members and never spills to parent-org members.
Encryption
- All traffic is encrypted in transit using TLS.
- Data at rest is encrypted by the underlying cloud platform.
- Selected fields containing personal health identifiers (e.g. MRN, DOB, SSN) are additionally encrypted at the application layer.
Auditing & monitoring
- An activity log records changes to tasks, issues, rocks, and comments.
- PHI access is recorded in an append-only, hash-chained access log that administrators can verify.
- Break-glass access for emergencies is time-bound, scoped, and logged.
- Administrators can run periodic access reviews and attest to them.
Data collection & use
We collect account data, workspace content you create, and operational telemetry such as IP, device, and crash reports. We use this data to run the service, send notifications you opt into, and improve reliability and security. We do not sell your data and we do not use workspace content to train third-party AI models. See the Privacy Policy for details.
Subprocessors & integrations
We use subprocessors for cloud hosting and database, transactional email delivery, push notifications, and AI model providers used inside features you explicitly invoke. Each subprocessor is required to meet equivalent security and confidentiality standards. Optional integrations (e.g. Microsoft calendar) only activate when you connect them.
Cookies & analytics
We use cookies and local storage strictly to keep you signed in and to remember your in-app preferences. We do not run third-party advertising trackers.
Retention & deletion
Workspace data is retained while your account is active. You can request account deletion at any time at /legal/delete-account; identifying data is removed within 30 days and encrypted backups are purged within 90 days.
Privacy requests
You can access, export, correct, or delete your data through in-app controls. EU/UK/CA residents have additional rights under GDPR / UK-GDPR / CCPA — email privacy@livegbx.com to exercise them.
Incident response & security contact
Report a security concern or suspected incident to security@livegbx.com. We acknowledge reports promptly and investigate. Confirmed incidents impacting your data are communicated to affected administrators.
Vulnerability reporting
We welcome responsible disclosure. Please send findings to security@livegbx.com with steps to reproduce. Please do not access data that isn't yours and do not run denial-of-service tests.
Compliance
LiveGBX is designed with HIPAA-aware controls — including PHI field encryption, access logging, MFA gating, and least-privilege roles — to help organizations operate workflows that involve protected health information. This page does not claim independent certification under HIPAA, SOC 2, ISO 27001, GDPR, or any other framework. If you need a Business Associate Agreement or a security questionnaire response, contact security@livegbx.com.