Skip to main content
Lightbridge Software A Lightbridge.ai company

Security and data architecture

Product Security and Data Architecture.

Lightbridge Software builds encryption at rest and in transit, role-based access controls, and full audit logging into every product from the first commit. The NetSuite extensions keep shipment, order, purchase order, and count data inside a customer's own NetSuite account, with no separate database. The Google Sheets Connector for Claude runs inside a customer's own cloud account, so Lightbridge has no runtime access to that customer's data or credentials.

One page for a security review, instead of several.

The technical facts about how Lightbridge Software's products handle data are already published, spread across the product pages that describe each build. A reviewer running a vendor security assessment should not have to reconstruct the architecture from separate marketing pages. This page collects those already-stated facts in one place: the engineering principles applied across every product, then the specific architecture of the NetSuite extensions and the Google Sheets Connector for Claude.

Everything here reflects what is shipped today. Where a claim describes work in progress, it is labeled as a roadmap item, not a statement about the current product.

Built in from the first commit, every product.

Encryption at rest and in transit

Every product encrypts stored data and every connection in transit. This is a first-commit requirement, not a feature added after a product ships.

Role-based access controls

Access to data and actions is scoped by role rather than granted broadly, so a user or a credential can reach only what the workflow in front of them requires.

Full audit logging

Every product logs the actions taken inside it: who did what, and when. The Barcode Inventory Counting scan log and the Google Sheets Connector's immutable audit trail are two shipped examples of the same discipline.

Transparent AI reasoning

Where a product uses AI, the reasoning behind a match score, a detection, or a recommendation is visible and auditable rather than returned as an unexplained result.

The NetSuite extensions: data stays inside NetSuite.

Predictive Third-Party Shipping Intelligence, Many-Destination Orders, Purchase Order Consolidation, and Barcode Inventory Counting are all SuiteCloud applications: SuiteScript, custom records, Map/Reduce processing, and Suitelets or RESTlets deployed through the SuiteCloud Development Framework. Shipment data, order hierarchies, purchase orders, and count records live inside the customer's own NetSuite account. There is no separate system of record holding a copy of that data and no nightly sync between platforms to secure.

Barcode Inventory Counting logs every scan with item, quantity, user, and timestamp, so a count can be reconstructed, a dispute resolved, or a recount validated against exactly what was scanned. Purchase Order Consolidation and Many-Destination Orders carry line-level traceability from the source sales orders through to the purchase orders and fulfillments they create, and user-event and client scripts protect data integrity on write.

The Google Sheets Connector for Claude: Lightbridge is not in the data path.

The Google Sheets Connector for Claude deploys into a customer's own cloud account and runs there. It authenticates to Google under least-privilege access scoped to the specific spreadsheets a workflow needs, stores those credentials encrypted under the customer's own key, gates destructive writes behind an explicit confirmation, and writes an immutable audit record of every action. Model use runs through the customer's own Anthropic account, so Lightbridge never brokers or resells model access. Lightbridge licenses the software on a subscription and operates no part of it at runtime, so it has no path to the customer's data, credentials, or spreadsheet content.

A large share of the work is structural: Claude writes a formula and Google Sheets computes the result, which keeps the arithmetic in the sheet rather than in the model. Two further steps are on the roadmap, not shipped today: a data-blind mode that would let Claude direct structural work without cell values reaching the model at all, and an attested-enclave configuration that would run any future data-touching work behind the customer's own encryption key.

Product architecture and website privacy are two different documents.

This page covers how the shipped products are architected to handle a customer's operational data once a product is in use: encryption, access control, audit logging, and where data lives. The privacy policy covers a different scope: how lightbridgesoftware.com itself handles a website visitor's information, including form submissions and browser tracking identifiers. A due-diligence reviewer typically needs both, read as separate documents rather than one.

Product security and data architecture: frequently asked questions

What security controls are built into Lightbridge Software products?
Every Lightbridge Software product is built with encryption at rest and in transit, role-based access controls, and full audit logging from the first commit, not added after launch. Where a product uses AI, the reasoning behind a score, a detection, or a recommendation is visible and auditable rather than an unexplained result.
Where does data live for the NetSuite extensions?
Predictive Third-Party Shipping Intelligence, Many-Destination Orders, Purchase Order Consolidation, and Barcode Inventory Counting are SuiteCloud-native applications. Shipment data, order hierarchies, purchase orders, and count records live inside the customer's own NetSuite account. There is no separate database or external system holding a copy of that data, and no nightly sync between systems to secure.
Does Lightbridge Software have access to my spreadsheet content or Google credentials?
No. The Google Sheets Connector for Claude deploys into the customer's own cloud account and runs there. Lightbridge licenses the software and operates no part of it at runtime, so it has no path to the customer's spreadsheet content, Google credentials, or the customer's own Anthropic account.
How does the Google Sheets Connector for Claude keep Lightbridge out of the data path?
The connector authenticates to Google under least-privilege access scoped to the specific spreadsheets a workflow needs, stores those credentials encrypted under the customer's own key, gates destructive writes behind an explicit confirmation, and writes an immutable audit record of every action. Because it runs entirely in the customer's own cloud account and is driven by the customer's own Claude, Lightbridge never receives the underlying data.
What audit trail exists for actions taken inside a Lightbridge Software product?
Each product keeps its own record. Barcode Inventory Counting logs every scan with item, quantity, user, and timestamp so a count can be reconstructed or a dispute resolved. The Google Sheets Connector writes an immutable audit record of every write it makes. Purchase Order Consolidation and Many-Destination Orders keep line-level traceability inside the NetSuite records they create.
Is this page the same as the Lightbridge Software privacy policy?
No, and the two cover different things. The privacy policy describes how lightbridgesoftware.com handles a website visitor's information: form submissions, browser tracking identifiers, and marketing attribution data. This page describes how the shipped products themselves are architected to handle a customer's operational data once a product is in use.
What is shipped today versus on the roadmap?
The Google Sheets Connector for Claude runs today entirely in a customer's own cloud account, driven by the customer's own Claude, with no Lightbridge runtime access. A data-blind mode that would keep cell values from reaching the model at all, and an attested-enclave configuration that would put data-touching work behind the customer's own encryption key, are architecture Lightbridge is building toward. Neither is a claim about the product today.
Who do I contact for a security questionnaire or a due-diligence request?
Send a security questionnaire or a due-diligence request through the contact page. Point a reviewer at this page first: it consolidates the specific, verifiable technical claims already published about each product's architecture in one place.

Running a security review?

Send a security questionnaire or a due-diligence request through the contact page, and point the reviewer at this page for the published technical detail behind it.