Utility data is sensitive. LRMS is built defense-in-depth — SOC 2 Type II managed hosting, strong encryption, database-enforced tenant isolation, and a hard line: no foreign-origin models, ever.
US jurisdiction, hardened configuration, 24/7 monitoring.
TLS 1.3 in transit, AES-256 at rest, encrypted database connections.
Row-level security enforced in the database engine — a utility_id on every row — so a query can't reach another utility's data even if the app layer slips.
Email codes and TOTP, configurable enforcement per utility, required for admin access.
Only US-based language models touch utility data. No foreign-origin models — ever. Every self-hosted model runs on US-based SOC 2 Type II compute.
Q&A, reasoning, and the Knowledge Center.
Self-hosted question answering.
Embeddings, image understanding, layout parsing.
Chinese-origin — never used.
Chinese-origin — never used.
Cryptographic anti-forgery tokens on every state-changing request.
100% parameterized PDO queries — no string-built SQL.
htmlspecialchars output encoding plus a Content Security Policy.
HttpOnly cookies, SameSite=Strict, 15-minute inactivity timeout.
Every change logged with user ID, timestamp, and IP — searchable and exportable.
Six roles from Super Admin to Board read-only.
LRMS is actively pursuing its own SOC 2 Type II certification, with the evidence trail being built now. For security inquiries, vulnerability reports, or draft SOC 2 documentation, get in touch.