Back to Terms

Technical and Organisational Measures — v1

Version 1.0 · Last updated 11 August 2026

1

Identity and scope

These Technical and Organisational Measures ("TOMs") are issued by Rwk Group Holding AB, Swedish company registration number 559544-6450, with registered address Törnrosvägen 74A, 181 61 Lidingö, Sweden, as operator of Lane Labs. They describe the Lane workspace controls within the scope stated below.

The measures reduce identified risks but do not guarantee absolute security, uninterrupted availability, perfect accuracy, complete isolation or zero retention. Customer-specific services, retention periods and additional measures apply only as stated in the Order Form and completed processing specification.

2

Access control

  • Protected requests are authorised on the server by validating an active session and applying role-based access and resource-membership checks.
  • Access to workspace resources is checked against the user's membership and role for the relevant resource.
  • Time-based one-time password (TOTP) multi-factor authentication is optional. Where a user enables it, Lane supports backup codes and session revocation. MFA is not mandatory unless the Order Form expressly requires it.

This version does not include a commitment to single sign-on (SSO), SCIM provisioning or any other identity-provider integration.

3

Connections, connector credentials and files

  • Lane uses HTTPS connections for browser, application and supported service communications. This appendix does not state a particular TLS version.
  • Stored connector credentials are protected using AES-256-GCM envelope encryption.
  • File access links issued by Lane are signed and time-limited.

The AES-256-GCM measure applies only to connector credentials. It is not a representation that all Customer Data, files, databases, logs or backups use that algorithm or that universal encryption at rest is provided.

4

Application and request protections

  • State-changing application flows use cross-site request forgery protections.
  • Cross-origin access is restricted through CORS configuration.
  • Rate limits apply to selected authentication and application endpoints.
  • Application responses include security headers intended to restrict content execution, framing, referrer information and unnecessary browser capabilities.

These controls are scoped to the flows and endpoints where they are implemented and do not constitute a universal web-application-firewall or denial-of-service commitment.

5

Workspace scoping

Lane is a logically scoped multi-customer service operating on shared infrastructure. Server-side session, role and resource-membership checks scope access to the relevant workspace and resource. This is logical separation, not dedicated physical infrastructure, a dedicated database or a representation that production row-level security policies are enforced for every data path.

6

Audit events

Selected security- and workspace-relevant events are written as append-only records and hash-chained to preceding records. This measure applies only to the selected event types implemented by Lane; it does not mean that every action is logged or that all logs are immutable in every underlying system.

7

Export, erasure and retention

Lane provides supported data-export functions and scheduled erasure workflows. The available export format, transition assistance, erasure trigger and applicable active-system, log, provider and legal-retention periods are those stated in the Order Form and completed processing specification.

Scheduled erasure is not a promise of immediate deletion from every system. Where protected backups or legally retained copies exist, they remain subject to the contractual retention schedule, restricted use and the deletion obligations in the DPA.

8

Matters not committed by version 1

Unless an Order Form expressly provides otherwise, version 1 does not commit to:

  • backup creation, backup locations, backup frequency, restoration testing, recovery point objectives or recovery time objectives;
  • EU-only, EEA-only, Frankfurt-only or other fixed processing or storage residency;
  • universal encryption at rest or any encryption algorithm for data other than connector credentials as stated in section 3;
  • zero data retention, provider zero-retention configurations or provider no-training terms;
  • ISO/IEC 27001, SOC 2 or any other certification or attestation;
  • SSO, SCIM or mandatory MFA;
  • a penetration-testing frequency, vulnerability-remediation service level, continuous monitoring or managed detection service; or
  • dedicated physical infrastructure or universal production row-level security enforcement.

Any no-training restriction in the DPA or Order Form remains a contractual processing restriction; it is not evidence of provider zero retention.

9

Customer responsibilities

The Customer remains responsible for lawful instructions, user and endpoint security, credential protection, workspace permissions, data minimisation, enabling optional MFA where appropriate, and human review of AI-assisted outputs. These responsibilities do not reduce Lane's duties under the DPA.

10

Version and changes

A contract must identify this appendix by version and date. A later change to the unversioned index does not modify an existing Agreement. Any replacement or materially changed schedule will be issued under a new version and handled under the notice and agreement provisions in the DPA and Order Form.

Technical and Organisational Measures v1 | Lane Labs