1. Overview
Lyraks Inc. ("Lyraks", "we", "our", or "us") designs and operates cloud platforms for modern business operations. Security is an essential part of how we build, manage, and improve our websites, applications, APIs, customer portals, and SaaS platforms.
This Security page describes the security practices, controls, and operational principles that support the Lyraks ecosystem. It is intended to help customers, partners, vendors, and users understand how Lyraks approaches platform security across its current and future services.
This page provides a practical overview of Lyraks' security approach. Specific customer commitments, service levels, and regulatory obligations are governed by the applicable written agreement with Lyraks.
2. Security Principles
Lyraks follows security principles designed to reduce risk and protect customer environments:
- Security by design: security considerations are included in platform architecture, development, deployment, and operations.
- Least privilege: access is limited to the level reasonably required to perform authorized functions.
- Defense in depth: multiple layers of safeguards are used across infrastructure, applications, data, and operations.
- Accountability: administrative access, system activity, and operational actions may be logged or reviewed where appropriate.
- Continuous improvement: security controls may evolve as threats, technology, laws, and customer needs change.
3. Cloud Infrastructure
Lyraks platforms may be hosted using reputable cloud infrastructure providers and supporting technology vendors. We use cloud infrastructure capabilities designed to support security, reliability, scalability, and operational resilience.
Infrastructure safeguards may include, where applicable:
- Network segmentation and protected cloud environments
- Firewall, routing, and traffic protection controls
- Secure configuration practices
- Environment separation between development, testing, staging, and production
- Backup, recovery, and service continuity processes
- Monitoring of service performance and infrastructure health
4. Access Control
Access to Lyraks systems is managed using identity and authorization controls designed to protect user accounts, administrative functions, and customer data.
Access controls may include:
- User authentication and account verification
- Role-based access permissions
- Administrative privilege restrictions
- Password and credential protection practices
- Session management and account activity controls
- Periodic review of access where appropriate
Customers are responsible for assigning appropriate roles, managing authorized users, removing inactive users, and protecting account credentials within their own organization.
5. Data Protection
Lyraks applies administrative, technical, and organizational safeguards intended to protect personal information, business data, customer records, and platform-generated data from unauthorized access, disclosure, alteration, loss, or misuse.
Data protection practices may include:
- Encryption or secure transmission protocols where appropriate
- Access restrictions for sensitive business records
- Logical separation of customer environments or records where applicable
- Audit trails and activity records for selected platform functions
- Secure data handling procedures for internal operations
- Retention and deletion practices aligned with customer agreements and applicable law
6. Backup & Recovery
Lyraks may use backup and recovery procedures designed to support service restoration and reduce the risk of data loss caused by technical failure, infrastructure disruption, or operational incidents.
Backup and recovery practices may include:
- Scheduled backups for selected systems and platform data
- Recovery procedures for critical service components
- Separation of operational environments where appropriate
- Periodic review of continuity procedures
- Infrastructure provider recovery capabilities where available
Backup availability, retention periods, recovery times, and restoration scope may vary by platform, customer plan, infrastructure provider, and written agreement.
6. Application Security
Lyraks develops and maintains software using practices intended to reduce common application security risks and improve platform reliability over time.
Application security practices may include:
- Secure coding principles
- Code review and development quality controls
- Dependency and package awareness
- Input validation and protection against common web vulnerabilities
- Authentication and authorization checks
- Change management for platform updates
- Testing before release where appropriate
8. Monitoring & Logging
Lyraks may collect logs, technical records, diagnostic data, and system activity information to support platform security, troubleshooting, performance monitoring, fraud prevention, and service improvement.
Monitoring activities may include:
- System health and availability monitoring
- Authentication and access activity logging
- Error and diagnostic logging
- Security event review
- API and integration activity monitoring
- Investigation of suspected misuse, unauthorized access, or abnormal activity
9. Incident Response
Lyraks maintains processes designed to identify, assess, respond to, and resolve suspected security incidents that may affect our systems, services, or customer data.
Incident response activities may include:
- Initial triage and validation
- Containment and mitigation
- Investigation and impact assessment
- Customer or regulatory notification where legally required
- Remediation and follow-up controls
- Post-incident review and improvement
If Lyraks determines that a security incident requires customer notification, we will provide notice in accordance with applicable laws, contractual obligations, and the nature of the incident.
10. Availability & Continuity
Lyraks designs its platforms to support reliable access to business operations. We may use backup, recovery, monitoring, and infrastructure redundancy practices to reduce service disruption and support continuity.
Availability may be affected by maintenance, emergency updates, third-party provider issues, internet conditions, customer-side configuration, security events, or circumstances outside Lyraks' reasonable control.
11. Customer Responsibilities
Security is a shared responsibility between Lyraks and its customers. Customers are responsible for how their users configure, access, and operate their accounts and platform environments.
Customers should:
- Use strong and unique passwords
- Protect login credentials and administrative accounts
- Assign users only the access needed for their role
- Remove users who no longer require access
- Review account activity where available
- Maintain accurate billing, contact, and security notification information
- Comply with applicable laws for data uploaded, stored, or processed through Lyraks platforms
12. Third-Party Integrations
Lyraks platforms may connect with third-party services such as payment processors, cloud infrastructure providers, communication systems, identity providers, analytics tools, and customer-selected business applications.
Third-party integrations may have their own security practices, privacy policies, availability standards, and contractual terms. Customers are responsible for reviewing and authorizing third-party integrations used with their Lyraks accounts.
13. Healthcare & Sensitive Data
Some Lyraks platforms, including CareCloud™, may support healthcare, wellness, appointment, patient, clinic, or sensitive operational workflows. Lyraks applies additional care to sensitive data handling where appropriate and where required by customer agreements or applicable law.
Healthcare organizations and other regulated customers remain responsible for determining their own legal obligations, configuring their accounts appropriately, and ensuring that their use of Lyraks services complies with applicable professional, healthcare, privacy, and data protection requirements.
14. AI & Automation Security
Certain Lyraks services may include artificial intelligence, analytics, workflow automation, or recommendation features. Where used, these technologies are intended to support business operations and improve user productivity.
Lyraks does not use customer confidential information to train public AI models without authorization. Customers remain responsible for reviewing automated outputs, validating business decisions, and ensuring that AI-assisted workflows are appropriate for their organization and regulatory environment.
15. Vulnerability Reporting
Lyraks welcomes responsible reporting of suspected security vulnerabilities. Reports should include enough detail for our team to understand, reproduce, and evaluate the issue.
When reporting a vulnerability, please avoid:
- Accessing, modifying, deleting, or extracting customer data
- Disrupting Lyraks services or customer environments
- Using social engineering, phishing, spam, or physical attacks
- Publicly disclosing a vulnerability before Lyraks has had a reasonable opportunity to investigate and address it
Please report suspected vulnerabilities or security concerns to security@lyraks.com.
16. Compliance Approach
Lyraks endeavors to align its security and privacy practices with applicable laws, customer requirements, and recognized security principles. Depending on the platform, customer agreement, and jurisdiction, relevant considerations may include Canadian privacy law, U.S. privacy and security requirements, healthcare-related requirements, international privacy principles, and industry-standard security practices.
This Security page is an overview of our general approach and does not replace customer-specific agreements, data processing terms, service-level commitments, or regulatory documentation where those are separately provided.
17. Important Limitations
No technology platform, network, system, or data transmission can be guaranteed to be completely secure, error-free, or uninterrupted. Lyraks uses reasonable safeguards designed to reduce risk, but security risks cannot be eliminated entirely.
Customers should maintain their own internal security programs, business continuity plans, compliance processes, staff training, and backup practices appropriate for their operations and risk profile.
18. Updates
Lyraks may update this Security page from time to time to reflect changes in our services, technology, operations, legal requirements, or security practices. Updated versions will be posted with a revised effective date.
19. Contact
For security questions, vulnerability reports, or security-related concerns, contact:
Lyraks Inc.
Security Team
Email: security@lyraks.com
Website: www.lyraks.com
For privacy-related inquiries, please contact privacy@lyraks.com or review our Privacy Policy.
← Back to Lyraks