Protecting the information entrusted to us by our customers, partners, and website visitors is a priority at Lantern LLC and its affiliates Lantern BRP, LLC and Lantern BRP Labs, LLC. This page describes the key elements of our security program. If you are evaluating Lantern as a vendor and need more detail than is appropriate to publish here, contact us at archana.haran@lanternglobal.ai. We’re glad to walk through our program directly, and additional documentation (including our SOC 2 materials, once available) can be shared under NDA.
Governance
Our security program is overseen at the executive level and is built around written information security policies covering access control, data classification, incident response, and vendor risk management. We conduct a risk assessment of our systems and practices at least annually.
Data Protection
- Encryption in transit. Data transmitted between your browser or systems and Lantern is encrypted using TLS.
- Encryption at rest. Data stored in our production systems is encrypted at rest.
- Data classification. We classify data based on sensitivity and apply handling controls accordingly.
Access Control
- Access to production systems and customer data is granted on a least-privilege, role-based basis.
- Multi-factor authentication (MFA) is enforced for administrative and internal system access.
- Access is reviewed periodically and revoked promptly upon role change or termination.
Infrastructure and Application Security
- Our infrastructure is hosted with AWS and other cloud providers, and we rely on our providers’ physical and environmental security controls for our hosting environment.
- We follow a secure development process that includes code review prior to deployment.
- We conduct periodic vulnerability scanning and third-party penetration testing.
Vendor and Subprocessor Management
We evaluate the security and privacy practices of service providers and subprocessors before engagement and on an ongoing basis, and we require appropriate contractual data-protection commitments from them.
Personnel Security
- Employees and contractors with access to sensitive systems are subject to confidentiality obligations.
- Security awareness training is provided at onboarding and on a periodic basis thereafter.
Incident Response and Business Continuity
We maintain a documented process for identifying, investigating, and responding to potential security incidents, including internal escalation procedures and, where required by law or contract, notification to affected customers or regulators.
Independent Assessment
Lantern has completed a SOC 2 Type I examination of its security controls. A SOC 2 Type II examination is currently in progress. Summary information or the applicable report is available to customers and prospective customers under NDA upon request.
Responsible Disclosure
If you believe you have discovered a security vulnerability affecting Lantern’s systems, please report it to tobias.lederberg@lanternglobal.ai, including a description of the issue and steps to reproduce it.
We ask that you:
- Give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly;
- Avoid accessing, modifying, or deleting data belonging to others; and
- Avoid any action that could disrupt or degrade our services, including automated scanning that generates significant load.
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy.
Contact
Security questions, and vulnerability reports, can be directed to archana.haran@lanternglobal.ai.