Security

Security That
Passes Muster.

Utility data is sensitive. LRMS is built defense-in-depth — SOC 2 Type II managed hosting, strong encryption, database-enforced tenant isolation, and a hard line: no foreign-origin models, ever.

Infrastructure

Hardened by Default.

🏢

SOC 2 Type II Managed Hosting

US jurisdiction, hardened configuration, 24/7 monitoring.

🔒

Encryption Everywhere

TLS 1.3 in transit, AES-256 at rest, encrypted database connections.

🧾

Tenant Isolation via Postgres RLS

Row-level security enforced in the database engine — a utility_id on every row — so a query can't reach another utility's data even if the app layer slips.

🔑

Multi-Factor Authentication

Email codes and TOTP, configurable enforcement per utility, required for admin access.

Institutional Knowledge Tools

US-Based LLMs Only.

Only US-based language models touch utility data. No foreign-origin models — ever. Every self-hosted model runs on US-based SOC 2 Type II compute.

US · Deployed

Claude (Anthropic)

Q&A, reasoning, and the Knowledge Center.

US · Deployed

Llama (Meta)

Self-hosted question answering.

US · Deployed

Granite (IBM)

Embeddings, image understanding, layout parsing.

Blocked

Qwen (Alibaba)

Chinese-origin — never used.

Blocked

DeepSeek

Chinese-origin — never used.

Application security

Defense in Depth.

CSRF Protection

Cryptographic anti-forgery tokens on every state-changing request.

SQL Injection Prevention

100% parameterized PDO queries — no string-built SQL.

XSS Prevention

htmlspecialchars output encoding plus a Content Security Policy.

Session Security

HttpOnly cookies, SameSite=Strict, 15-minute inactivity timeout.

Complete Change History

Every change logged with user ID, timestamp, and IP — searchable and exportable.

Role-Based Access

Six roles from Super Admin to Board read-only.

Compliance

Both the App and the LLM Compute Run on SOC 2 Type II Infrastructure.

LRMS is actively pursuing its own SOC 2 Type II certification, with the evidence trail being built now. For security inquiries, vulnerability reports, or draft SOC 2 documentation, get in touch.