Security
Last updated June 2026
MacrosLM handles sensitive financial documents. Protecting them — and your clients' — is foundational to how the product is built and operated.
Compliance
MacrosLM is independently audited against the SOC 2 framework — both Type I (controls are designed correctly at a point in time) and Type II (controls operate effectively over a sustained period). Reports are available to customers and prospects under NDA.
Encryption
All traffic to and from MacrosLM is encrypted in transit with TLS. Data — including the files you upload and the deliverables we generate — is encrypted at rest. Encryption keys are managed by our cloud provider and rotated on a regular basis.
Infrastructure
MacrosLM runs on enterprise-grade cloud infrastructure with network isolation, hardened configurations, and automated, encrypted backups. Production access is restricted, logged, and reviewed.
Access control
We follow the principle of least privilege. Internal access requires SSO with enforced multi-factor authentication, is scoped to what each role needs, and is logged for audit. Access is reviewed regularly and revoked promptly when no longer required.
Data handling & retention
The files you provide are processed solely to produce your deliverables. We retain your data only as long as needed to provide the service or as you direct, and we delete it on request. Your data is never sold.
Data privacy (GDPR & CCPA)
MacrosLM supports compliance with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We process personal data on a lawful basis and honor data-subject rights — access, rectification, erasure, and portability — along with the rights of California residents to know what we hold, request deletion, and opt out of the sale of personal information. We do not sell personal data. A Data Processing Agreement (DPA) is available to customers on request, and we maintain transparency over the sub-processors we rely on.
Responsible disclosure
If you believe you've found a security vulnerability, we want to hear from you. Email security@macroslm.com and we'll respond promptly. Please give us reasonable time to investigate and remediate before any public disclosure.