Skip to main content
Security and privacy

Your health data stays private.

Lysco is built for sensitive medical documents. The controls below explain what we encrypt, what staff can and cannot see, and what you can delete yourself.

What matters most

Eight protections, built in.

Account access is isolated

Row-level security helps keep one user’s records separate from another. Narrowly authorized operational access is separately controlled and logged.

Account files go straight to storage

Signed one-time links send account file uploads directly into private storage instead of routing the file bytes through the web application.

Download links expire

Links that open your files stop working after 5 minutes, so an old link is useless to anyone who finds it.

Selected fields are locked twice

Extracted text, case analysis, letters, member IDs, bill line items, and assistant memory receive application-level encryption in addition to provider encryption at rest. Not every database field has this second layer.

A computer reads it, not a person

Staff do not open your case in normal operation. Narrowly authorized access may occur for requested support, security, abuse investigation, or a legal obligation; supported admin actions are logged.

Delete it yourself

Delete a case or account from Settings. The flow removes active records and files and reports a warning if cleanup is incomplete; provider backups age out on their own lifecycle.

Recorded sensitive actions

Uploads, signed document access, profile changes, exports, deletions, and consent events are recorded. Not every server-rendered or internal read creates a separate account-visible event.

Scrubbed from our logs

Details like member IDs and Social Security numbers are automatically scrubbed from our system logs.

Plain-English promise

No fine-print surprises.

  • We never sell your health data.
  • We never send your data to insurers. You choose what to submit.

Health-data safeguards

Lysco is a consumer tool you upload your own documents to — not a healthcare provider, health plan, or clearinghouse — so Lysco is not a HIPAA "covered entity" or "business associate." The protections above are applied voluntarily; they are not a HIPAA certification. Our Privacy Policy documents their current scope and exceptions.

Privacy policy

Responsible disclosure

If you spot a security issue, send a short note to our security team. We review reports quickly and take verified issues seriously.

security@lysco.com

Ready to check a document?

Start free. No credit card required.

Start free