Security at Lensix
We're asking you to give Lensix visibility into your cloud infrastructure. That's a real decision, and we built the product around earning that trust — not just asking for it. Here's how we protect your account, your data, and your cloud access.
The most important control: read-only, always
Lensix connects to your AWS, Azure, or GCP account using the lowest-privilege read-only role each provider offers. It is not possible for Lensix to create, modify, or delete anything in your environment — there is no code path that makes a write API call. The credentials live entirely in your own cloud account, and you can revoke access instantly by deleting the role, at any time, without contacting us.
Prefer not to grant live access at all? You can generate a point-in-time inventory file yourself and upload it instead — that path shares zero cloud credentials with us, ever. And if that gathering process happens to encounter something that looks like a hardcoded secret along the way, only the fact that one was found is recorded — never the value itself.
See the full breakdown of our cloud access model →Account & access
Protecting your account
Passwords are never stored in plain text
Passwords are protected with industry-standard adaptive hashing, designed specifically to resist brute-force and offline cracking attempts. We never see or store your password in a readable form.
Optional two-factor authentication
Any user can enable authenticator-app-based two-factor authentication on their account, and organization admins can require it for their entire team.
Strict tenant isolation
Every organization's data — accounts, findings, resource inventory, everything — is logically isolated from every other organization at the data layer. There is no shared view across customers.
Role-based access control
Admins and members have distinct permission levels within an organization, and a separate internal-staff-only tier exists for platform administration — it never has standing access to customer cloud credentials.
Revocable, monitored sessions
Sessions are tied to a server-side record that can be revoked instantly — from a password change, a role change, or a manual sign-out — rather than simply expiring on their own schedule.
Automated brute-force protection
Login and other sensitive account actions are rate-limited to slow down and block automated guessing attempts.
Least privilege applies internally too
Different parts of our own systems hold only the specific, narrow credentials they need to do their job — the systems that serve your dashboard never hold the credentials used to run a scan, and vice versa. A problem in one place doesn't cascade into access it was never granted.
Locked-down session cookies
Your session cookie can't be read by page scripts, is never sent over an unencrypted connection, and is restricted from being sent by other sites — standard defenses against cookie theft and cross-site attacks.
Application & data
Protecting your data
Encrypted in transit, always
Every connection to Lensix — your browser to our application, and our systems to your cloud provider — is encrypted using HTTPS/TLS. Unencrypted connections are not permitted.
Encrypted at rest
Data we store about your cloud resources and findings is encrypted at rest, not just protected in transit — so it's protected on disk, not only on the wire.
Modern browser security controls
We deploy current browser-enforced protections against common web attacks such as clickjacking, content injection, and cross-site scripting.
Secure development practices
Our engineering practices are built around preventing common classes of vulnerabilities — injection, unauthorized cross-account data access, and server-side request forgery among them — with reviews built into how we ship changes.
Ongoing dependency and vulnerability management
We monitor the software components Lensix is built on for newly disclosed vulnerabilities and patch promptly, rather than on a fixed calendar schedule.
We read metadata, not your data
Lensix's checks read cloud resource configuration — things like whether a bucket is public or a database has backups enabled. We do not read, transfer, or store the contents of your files, databases, or secrets.
Found a security issue?
We take reports from the security community seriously. If you believe you've found a vulnerability in Lensix, please tell us before disclosing it publicly — we'll investigate promptly and keep you updated.
[email protected]Security questionnaire or vendor review?
If your team needs to complete a vendor security review before rolling out Lensix, we're glad to work through it directly.
Get in touch →See it for yourself
Free to start, no credit card required. Connect a read-only role and see exactly what Lensix sees.
Create an account
