> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ltv.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> How LTV.ai protects your data and your customers' data

## Infrastructure

LTV.ai runs on Amazon Web Services. Application data is held in managed AWS services, and analytics data in a managed data warehouse.

All traffic to and from LTV.ai is encrypted in transit.

## Access control

<CardGroup cols={2}>
  <Card title="Workspace isolation" icon="layer-group" href="/manage/workspaces">
    Access is granted per workspace. A user with access to one brand cannot read another brand's data.
  </Card>

  <Card title="Authenticated sign-in" icon="key" href="/manage/workspaces">
    Magic link or password. Access is provisioned and revoked by the LTV.ai team.
  </Card>
</CardGroup>

When a user's access to a workspace is revoked, it takes effect on their next request. See [Workspaces](/manage/workspaces).

## Payment data

LTV.ai does not store card numbers or payment credentials. Payments are handled by Stripe. See [Billing](/manage/billing).

## Customer data you send us

LTV.ai holds the customer data required to run your campaigns: contact details, purchase history, and email engagement history. It is used to segment, personalize, and report on your campaigns for your brand only.

Your customer data is never used to serve another LTV.ai customer.

## Reporting a vulnerability

If you believe you have found a security issue in LTV.ai, contact your account manager or email <a href="mailto:security@ltv.ai">[security@ltv.ai](mailto:security@ltv.ai)</a> with enough detail to reproduce it. Please do not disclose it publicly before we have had a chance to respond.

## Security documentation

For a security review, vendor assessment, or questionnaire, contact your account manager. They can supply current documentation on certifications, encryption standards, retention schedules, authentication options, and access controls for your organization's review.

<Note>
  If your organization requires specific controls such as enforced multi-factor authentication, IP restrictions, or a signed data processing agreement, raise them with your account manager before rollout rather than after.
</Note>
