Lightcourt

Security

How Lightcourt keeps every company apart

Most tools that bring your work together pool it first. Lightcourt does the opposite: it unifies your attention while refusing to unify the confidential information underneath.

Separated by design

See what needs you. Each organization sees only itself.

Each Space has its own key, its own data and its own AI policy. Lightcourt combines them only on your device, and only into what needs you. There is no path from one company’s data to another’s.

See it from their side Choose who’s looking.
Personal Own key · own data
Your device Combined here, for you only

Northstar, Studio and Personal each send only what needs you to your device. No arrow connects Northstar and Studio.

Northstar A company you work for

Can see

  • That Lightcourt is connected to Northstar’s own systems — its admins can see the connection.
  • What you do in Northstar’s systems, like a reply you send from Northstar mail.
  • Its own connection events: authorized, synced, revoked.
  • A time you propose for a Northstar meeting: its start and end.

Can’t see

  • Which other organizations or accounts you have connected.
  • Mail, chat, events or titles from Studio or Personal.
  • How many Spaces you have, or that any others exist.
  • Your drafts, searches, or what you looked at.

Studio A company you work for

Can see

  • That Lightcourt is connected to Studio’s own systems — its admins can see the connection.
  • What you do in Studio’s systems, like a reply you send from Studio mail.
  • Its own connection events: authorized, synced, revoked.
  • A time you propose for a Studio meeting: its start and end.

Can’t see

  • Which other organizations or accounts you have connected.
  • Mail, chat, events or titles from Northstar or Personal.
  • How many Spaces you have, or that any others exist.
  • Your drafts, searches, or what you looked at.

Lightcourt Us, as your vendor

Can see

  • Your account email and how you sign in.
  • Your plan, seats, invoices and whether they’re paid.
  • Opaque ids and dates, for support and billing.

Can’t see

  • The names of your Spaces, or how many you have.
  • Which apps or organizations you’ve connected.
  • Anything inside a Space: mail, chat, events or drafts.

Stripe Payments

Can see

  • Your account email, plan, seats and the amounts you pay.
  • Your card details — Stripe holds them, Lightcourt never does.

Can’t see

  • Your Space names, how many Spaces you have or which apps you connect.
  • The organizations you work for, or anything inside a Space.

Lightcourt cannot hide the fact that it exists as a vendor or that it was authorized in an organization’s own environment.

  1. Every Space is sealed

    Each company you add becomes a Space with its own encryption key, its own data and its own runtime. There is no path from one company’s data to another’s.

    • A request can only reach the one Space its access token names.
    • Asking for another Space’s data fails exactly like asking for something that doesn’t exist.
    • Connector tokens never reach the browser, logs or AI prompts.

    INV-02 · INV-03 · INV-11 · INV-19

  2. Combined only on your device

    Today, Inbox, Chat and Calendar are built on your device from separate requests, one per Space. No server returns more than one Space.

    • Cross-Space ranking uses only priority, minutes and busy times — never senders, titles or text.
    • Search stays inside the Space you’re in unless you ask for more.

    INV-01 · INV-08 · INV-09

  3. Honest about what each company can see

    An organization may see that Lightcourt is connected to its own systems. It cannot see, query or infer which other organizations or accounts you have connected.

    • Every enterprise connector shows an Admin Visibility Preflight before you sign in.
    • Each company’s view looks the same whether you have one Space or ten.
    • Its audit view shows only events about its own systems.

    INV-05 · INV-18 · INV-21

  4. AI stays inside its Space

    Every Space has its own model policy. The default uses local rules only; a model provider runs in a Space only if you choose it there.

    • What a message says is treated as data, never as instructions — so a message can’t send a model into another Space.
    • There is no AI that reads across every company at once.

    INV-10 · INV-13

  5. Nothing goes out without you

    Replies are drafted in the Space they came from, from that company’s account. Anything that writes to a company’s systems waits for your approval and passes a policy check first.

    • The From line is fixed to the thread’s Space. There is no account picker to get wrong.
    • A new meeting time carries only its start and end — never what it clashed with.
    • Nothing is copied between calendars, not even a Busy block.

    INV-12 · INV-14

  6. Quiet by default, gone when deleted

    Notifications say how many things need you in a Space, not what they say, unless you turn previews on for that Space. Deleting a Space destroys its key, so its data can’t be read again.

    • Logs and audit records never contain message text, titles or prompts.

    INV-15 · INV-16 · INV-17

What we don’t claim

  • Lightcourt cannot hide the fact that it exists as a vendor or that it was authorized in an organization’s own environment.
  • We don’t claim any certification.
  • We never tell you an organization’s admins can’t see the connection to their systems. They can, and Lightcourt doesn’t try to hide it.

Report a security issue

Found something? Email us and we’ll reply. Please don’t test against other people’s accounts.

Email the security team