Security statement
What we can verify.
This page states the current limits plainly. Missing evidence is not replaced with a badge, promise, or implied control.
- Certifications
- Litos does not currently claim SOC 2, ISO 27001, HIPAA, or any other security certification.
- Encryption
- The production website is served over HTTPS. Litos does not currently publish an independently verified specification for encryption at rest, so we do not claim one here.
- Data residency
- Litos does not currently offer a customer-selectable data region or publish a verified data-residency commitment.
- Access controls
- Litos does not currently publish an audited access-control report. Requests to access or delete account data follow the process described in the Privacy policy.
- Independent testing
- Litos has not published a third-party penetration test or independent security audit.
- Incident record
- There are no public security incident disclosures listed as of 10 August 2026. This is a disclosure record, not an uptime or no-incident claim.
Report a vulnerability.
Litos does not operate a bug bounty. Use the contact form and choose Technical problem. Do not include secrets, passwords, or private account data in the first message.
Statement dated 10 August 2026