A Plain-Language Document

Trust & Security

Effective 16 July 2026  ·  v1

Before you trust software with any part of your business, you deserve to know exactly how it handles your data — and where it honestly stands on the audits people ask about. This page answers both in five minutes, without a single claim we could not defend.

1. The Short Version

LORE holds very little of your data, protects what it does hold with named, industry-standard controls, and never sells any of it. Our products — including the Operator OS — are self-install and run on infrastructure you own, which means the operational data flowing through your installation stays with you: LORE does not host it, log in to it, or process it. The less of your data we hold, the less there is to protect — and that is by design.

2. Where Your Data Lives

What LORE holds — the record of your relationship with us: your name, email, billing address, what you bought, the amount, and the Stripe charge identifier. That is nearly all of it.

What LORE never holds — your payment card numbers (handled entirely by Stripe; LORE never sees them) and the operational data inside your own LORE installation (it runs on your infrastructure, not ours). We cannot lose what we never hold.

3. How We Protect It

Payments — processed on Stripe's PCI-DSS Level 1 infrastructure, the highest tier of the card-industry security standard. LORE never receives or stores card details.

Email & documents — held in Google Workspace with mandatory two-factor authentication on every account.

Infrastructure — LORE's internal automation runs on a server reachable only by SSH key (no password login), behind Cloudflare on every public endpoint, with credentials rotated and never committed to code. Automated backups redact secrets before they are ever written.

Email authentication — LORE's sending domain is protected by SPF, DKIM, and an enforcing DMARC policy, so mail claiming to be from LORE can be verified as genuinely ours.

Continuous monitoring — production is watched around the clock by LORE's automated Watchman, which surfaces anomalies for review rather than waiting for a scheduled check.

4. Who Touches Your Data

A small, named list of trusted vendors (subprocessors) handles parts of the operation. Each is contractually bound to handle data only as needed:

We do not sell or rent your personal information. LORE shares information only when legally required, when necessary to protect rights or prevent serious harm, or as part of a business transition with prior notice to existing customers.

5. Access & Accountability

Access to LORE's systems is limited to what each part of the operation actually needs, secured with two-factor authentication and key-based login. Credentials are rotated, and secrets are kept out of source code and redacted from backups. The workflows that fulfill LORE products are backed up on a fixed schedule so a build can always be restored.

6. Certifications & Compliance — Stated Plainly

We would rather tell you exactly where we stand than imply a badge we have not earned.

SOC 2 — LORE is not currently SOC 2 audited. SOC 2 is an independent auditor's report on a company's security controls; it is typically pursued when an enterprise customer's procurement process requires it. LORE maintains its controls to that standard's intent and can begin a formal SOC 2 engagement when a customer's requirements call for one. If that is a gate for your organization, tell us and we will scope it.

HIPAA — HIPAA governs Protected Health Information handled for healthcare organizations. LORE's products serve real-estate operators and do not collect, process, or store health information, so HIPAA does not currently apply to our service. If your use case involves health data, that is a conversation to have with us and with counsel before you proceed — we will not overstate our coverage.

Privacy law — LORE's data practices are built to CCPA/CPRA, GDPR/UK GDPR, and CAN-SPAM standards. The full detail lives in our Privacy Policy.

Payment security — card handling runs entirely on Stripe's PCI-DSS Level 1 platform, so LORE itself never processes or stores card data.

7. If Something Goes Wrong

If LORE ever experiences a breach affecting your personal data, we will notify you promptly — within 72 hours of confirmed discovery — with a plain-language description of what happened, what data was affected, what we are doing about it, and what you should do. No burying it, no delay.

8. Your Rights Over Your Data

You may ask us to access, correct, or delete the data we hold (except records we are legally required to keep), request a copy, or withdraw consent. To exercise any of these, email mark@loreinc.global — no form, no charge, no need to justify the request. Full detail is in our Privacy Policy.

9. Questions From a Buyer or Security Team

If you are evaluating LORE for your organization and need a security questionnaire completed, a subprocessor list, or a written summary of our controls, email mark@loreinc.global and we will respond directly. We would rather answer a real question than point you at a badge.

10. Changes

When we update this page, we update the "Effective" date and publish it at the same URL. Material changes to how we protect customer data are communicated to customers by email.

11. Contact

mark@loreinc.global

LORE LLC  ·  30 N Gould Street, Suite N, Sheridan, WY 82801  ·  EIN 42–2306789

v1  ·  Effective 16 July 2026  ·  Veritas et Lux