Built so the strongest claims are the true ones. Then audited.
Lens is designed to need no trust in LockFlare: nothing installed on your servers, no credentials at LockFlare, no connection from Lens to us. The certification is the other half — proof that the company behind the software is run to the same standard.
ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for information security management. Certification means an independent, accredited auditor examined how LockFlare Corp establishes, runs and maintains its security controls — and found them implemented and effective, not merely written down.
The management system covers the whole lifecycle of what we ship: how Lens and Cipher are built and released, how the licensing service that issues your keys is run, the infrastructure, the people, and the processes around them. It is maintained under formal document control and re-audited on the standard's cycle.
The certificate
We share the certificate itself on request rather than publishing it: ask for it and it comes from a signed account.
The Hacker News Awards 2026
Winner, Excellence in Cybersecurity Innovation, in the Runtime Security category — for running code on servers you do not fully trust without a readable byte on disk, and for the same discipline carried into Lens: a console that manages a fleet with nothing installed and nothing passing through us.
The award, on thehackernews.comWhat backs the certificate
A complete Information Security Management System: policies, procedures and operational runbooks covering the Annex A controls assessed under ISO/IEC 27001:2022. We don't publish the library; we walk through it with you.
ISMS Scope Statement
What the management system covers — products, the licensing service, infrastructure, people and process — and the boundaries of the audit.
Statement of Applicability
Every Annex A control: applied or excluded, justified, and mapped to how LockFlare implements it.
Any control area you name
Security or procurement review needs one area in depth — access control, cryptography, supplier management, incident response — and our engineering team reviews it with you directly.
The Scope Statement and the Statement of Applicability are available under NDA. Request documentation.
What the software makes unnecessary
Most of a vendor security review asks what happens to your data on the vendor's side. With Lens, the honest answer is that there is no vendor side.
No server of ours in the path
Lens connects to your servers over your own SSH logins. It never opens a connection to LockFlare — not for a license check, not for telemetry. There is nothing for us to log.
No credentials held by us
Logins, keys, sudo passwords, certificates and API keys live on your computer, sealed under the pen drive's own signature. There is no store on our side to breach.
Two facts about you, and only two
The email on your account and the IP addresses you license — because a server license is written for one address. That is the whole of what the licensing service holds.
Every action, on your servers' own record
What Lens changes is written to a signed ledger on the box, and every sudo command it runs appears in that server's own journal, like any operator's would.
Questions about our security posture?
Our engineering team answers directly: the ISMS, the Statement of Applicability, the certificate, and anything your compliance process requires.