LEGAL

Security

Effective July 2026

How we protect your notes. NoteX is built by a company that serves governments and enterprises, and the security model reflects that.

Local-first by architecture

The desktop app works entirely offline with files on your disk. What never leaves your machine cannot leak from ours. Cloud sync is opt-in, per workspace, and a Local workspace that never syncs is always available.

In transit and at rest

All traffic to our servers is encrypted with TLS. Synced notes, attachments, and workspace data are stored on managed infrastructure with encryption at rest.

Access control

  • Private-space notes are visible only to their owner; workspace notes follow workspace membership.
  • Share links carry view, comment, or edit permission and optional expiry.
  • API keys are scoped (read-only or read/write, optionally page-scoped), stored hashed, expiring if you choose, with per-request logs.

A curated extension surface

The desktop app ships deny-by-default: only extensions on the curated allow-list install, and enterprise teams control their own list. Extensions come from Open VSX, and AI add-ons run under your own provider accounts.

Your data is not training data

We never train AI on your notes, and desktop AI add-ons talk to providers directly under your accounts rather than through our servers.

Deployment options

  • Local only: no account, no server, files on your disk.
  • Lisan Cloud: the default sync backend, fastest way to collaborate.
  • Self-hosted: enterprises point desktop clients at their own Supabase-compatible server, so synced notes stay inside their network.

See workspaces & servers for the full picture, or talk to us about your requirements.

Responsible disclosure

Found a security issue? Email support@lisan.com and we'll work with you. Please don't test against other customers' data.