BUILT FORZERO TRUST.
Lengdon assumes no party should be trusted by default — including us. Every control exists to protect both parties from each other, from the platform, and from time.
EIGHT CONTROLS.
ALL MANDATORY.
Encryption at rest and in transit
All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed per-room and rotated at close. No Lengdon employee has access to transaction content.
Per-person NDA enforcement
Every participant — not every company — signs an individual NDA before accessing the room. Access is granted to named individuals, not to organisations or teams. There is no 'company-level' access.
Append-only, tamper-evident record
Every action taken in a room is written to an append-only log. No entry can be deleted, modified, or reordered. Altering any earlier entry is detectable — the record makes tampering evident, not merely logged.
Multi-factor authentication
MFA is mandatory for all participants in every room. There is no mechanism to disable it. Authentication events are recorded individually in the audit log.
Role-scoped access
Each participant receives only the access their role requires for the current gate. Documents not yet released at the current gate are inaccessible — not hidden, not locked — simply not visible to the other party.
No money movement
Lengdon never handles, holds, escrows, or routes funds. Payment confirmation is recorded — proof of transfer is uploaded and counter-confirmed — but no financial instrument passes through our infrastructure.
Data residency
Transaction data is stored in the jurisdiction elected at room creation. UK, EU, and US options are available. Data does not leave the elected jurisdiction. For institutional requirements, additional residency options are available on request.
Independent record
Both parties receive a copy of the full audit trail at close. The record is independent of the Lengdon platform — it documents exactly what happened without requiring access to our systems.
THE APPEND-ONLY
RECORD.
Every action is written to a permanent, append-only log where each entry references the one before it. Altering an earlier entry breaks that reference — visibly, and permanently.
Condition Met: Regulatory Approval
ATLS01-ROM-2026-000017-91Term Accepted: Board Seat
ATLS01-ROM-2026-000018-88Document Released: Cap Table
ATLS01-ROM-2026-000019-85Full technical documentation of our security controls and encryption implementation is available on request for institutional due diligence.