Back to home

SOC 2 compliant

Security built in, not bolted on.

Lytica connects to the systems that run your business, so trust is the product. Here's how we protect your data — from authentication to every action Marli takes.

Authentication & access

Only the right people, only the right data.

Enterprise SSO with WorkOS

Sign in through WorkOS AuthKit with your existing identity provider. No separate Lytica passwords to manage, rotate, or leak.

Role-based access control

Admin, Member, and Viewer roles scope what each person can see and do. Access is granted per organization, not shared across tenants.

Per-organization isolation

Integration credentials and data access are scoped to your organization. Channel-partner deployments can run on fully isolated instances.

Connections & actions

Your data stays yours — and under your control.

OAuth-first, no stored passwords

Managed connections authenticate through official OAuth flows. For providers managed via WorkOS, tokens are fetched per call — we never store your provider passwords.

Read-only by default

Marli reads the data it needs to answer your question. Reads never mutate your systems, and you control which integrations are connected.

Writes require your approval

Any action that changes or sends data — creating records, sending messages, deleting — is surfaced for explicit human confirmation before it runs, and logged in the conversation.

Disconnect anytime

Revoke any integration with one click. Disconnecting immediately stops Lytica from accessing that source.

Compliance & questions

Lytica is SOC 2 compliant. Need our report, a security review, a DPA, or answers to a vendor questionnaire? Our team will get you what you need.

Contact our security team