September 17, 2026

Privacy policy

Welcome to Asset. This Privacy policy explains how we collect, use, and protect your personal information when you use our website.

1. Cloud Infrastructure & Database Security

Lexera’s backend infrastructure is engineered to provide absolute cryptographic isolation and data sovereignty for high-stakes legal workflows.

Postgres & Row-Level Security (RLS): Our core database infrastructure utilizes Supabase, enforcing strict Row-Level Security policies. This ensures that cross-tenant data access is cryptographically impossible, isolating your proprietary corporate playbooks and agentic payloads.

Encryption at Rest & in Transit: All contract payloads, system prompts, and escrow states are encrypted at rest using AES-256 and transmitted exclusively via TLS 1.3 protocols.

Stateless Processing: Localized statutory audits performed by our Core AI operate purely in-memory. Once the verification routing is triggered, transient data is systematically purged.

2. Absolute Limitation of Liability

2. Protocol & Transport Security

As a protocol operating natively within the agentic economy, we secure the entire transmission lifecycle between your AI agents and our human network.

Model Context Protocol (MCP) Integrity: Communication between your orchestration gateways (such as OpenRouter or LangChain) and Lexera requires strictly authenticated Bearer tokens to prevent unauthorized tool execution.

Secure Asynchronous State (SSE): We manage the long-running wait times associated with human legal review via highly secure Server-Sent Events (SSE). This maintains a persistent, deterministic connection without exposing continuous webhook vulnerabilities to your internal network.

Payload Validation: Every incoming contract payload undergoes strict schema validation against our mcp-manifest.json before being accepted into the routing pipeline, rejecting malformed or malicious code injections natively.

3. Escrow & Transactional Integrity

The financial routing layer of Lexera is designed with zero-trust principles to protect enterprise capital and ensure verifiable legal sign-off.

Atomic Escrow Holds: When a contract is routed to the partner network, a cryptographic hold is placed on the pre-funded API wallet. Funds are exclusively released upon the receipt of a verifiable digital signature from the human attorney.

Immutable Audit Trails: Every state change within the protocol—from the initial AI generation to the final attorney sign-off—is logged immutably. This creates a legally defensible chain of custody for enterprise risk management.

Escrow Access Control: Multi-signature executive controls can be enforced on the Custom Pipeline tier, ensuring that high-value transaction routing cannot be autonomously triggered by an agent without authorized human intervention.

4. Application & Access Control

We provide robust access management to ensure that only authorized developers and legal operators can configure your verification pipelines.

API Key Management: Enterprises can generate, rotate, and revoke scoped API keys instantly via the Lexera dashboard to control specific agentic workflows.

Role-Based Access Control (RBAC): The Custom Pipeline tier supports strict RBAC, ensuring that developers can access the MCP sandbox while only designated legal administrators can modify the proprietary corporate playbooks or approve escrow limits.

5. Jurisdictional Data Sovereignty

Because Lexera bridges code and physical law, our data routing strictly adheres to regional compliance mandates.

Geofenced Verification Routing: Contract data designated for verification is routed exclusively to vetted partner law firms physically residing and operating within the United Arab Emirates (Federal & DIFC) and Jordan.

Regulatory Alignment: Our data handling procedures are mapped to comply with UAE and DIFC data protection frameworks, ensuring that cross-border enterprise operations maintain full regulatory compliance.

6. Vulnerability Management

Lexera maintains an active, continuous defense posture against emerging threats in both the Web3 and AI ecosystems.

Continuous Monitoring: Our production infrastructure is monitored 24/7 for anomalous API calls, sudden spikes in escrow routing, or unauthorized protocol access attempts.

Automated Threat Detection: We deploy active rate limiting and DDoS mitigation at the edge to ensure the protocol remains highly available for mission-critical enterprise workflows.

9. Contact Us

If you have questions, contact us at hello@lexera.dev

6. Vulnerability Management