LEGAL
Security & Data Handling
Our commitments on how client material is handled, how private models stay separate, and how to report a vulnerability.
Last updated August 16, 2026
01Our approach
We are a small team, and our security posture reflects that: few systems, few people with access, and clear rules about client material. This page states our practices and commitments. It is not an audit report or a certification claim, and it does not claim compliance with any specific standard or framework.
We aim to keep reasonable administrative, technical, and physical safeguards appropriate to our size and the sensitivity of the data we handle, consistent with Texas Business & Commerce Code Chapter 521 and the data-security duty in the Texas Data Privacy and Security Act.
02Data handling
- Client material is transferred over encrypted connections.
- Access is limited to the engineers working on your engagement.
- Material is stored only where it is needed for the work, and removed when the engagement or agreed retention period ends.
- We do not share client material with other clients, and we do not sell it.
03Model isolation
Each client's model is trained and run for that client alone. One client's data is never used to train another client's model. Where an engagement calls for it, a model can run on hardware inside your own premises.
We do not sell client data, and we do not collect biometric identifiers for commercial purposes. If a project ever required them, we would obtain the informed consent that Texas Business & Commerce Code Chapter 503 requires before any capture.
04Access control
Accounts are individual, protected by strong authentication, and reviewed when someone's role changes or they leave. Credentials are never shared over unencrypted channels.
05Breach response and notification
If an incident affects your data we will investigate, contain it, and contact you with what we know, what is affected, and the steps we are taking.
Where sensitive personal information is involved, we follow the Texas notification law (Texas Business & Commerce Code, Chapter 521): we notify affected individuals without unreasonable delay and no later than 60 days after determining a breach occurred, and we notify the Texas Attorney General within 30 days when a breach affects at least 250 Texas residents. Where we act as your processor, we notify you promptly so you can meet your own notification duties, and we support you in doing so.
06Reporting a vulnerability
Email contact@lonestarprivateai.com with the details and steps to reproduce. Please give us a reasonable window to fix an issue before disclosing it publicly, and do not access or modify data that is not yours while testing. We appreciate reports made in good faith and will acknowledge yours.
07Your obligations
Security is shared, and some rules are legal ones. Keep your own accounts and devices protected, restrict who can reach the systems we connect to, and tell us promptly if you suspect a compromise on your side.
Questions about this document? Email contact@lonestarprivateai.com or write to Lonestar Private AI, 1942 W Gray St #1522, Houston, TX 77019.