What we don't store.
Listor is unusual, because we never receive your policy content. We store a title, a URL, and the attestation that someone read it. The policy itself stays wherever you already keep it. That changes the security conversation.
Architecture
Link-only, by design.
Your documents live in Notion, Confluence, Drive, or your own intranet. Listor never sees the bytes, only the URL and the moment someone confirmed they read it.
Stays with you
Your document
Notion, Drive, Confluence, your intranet
- The policy text
- Every past version
- Attachments and comments
boundary
Reaches Listor
Listor
Four fields, and nothing else
- The title you typed
- The URL you pasted
- Who attested, and when
- Their IP and browser
Your employees open the link and read the policy where it already lives. Listor records that they did.
The rest is standard hygiene.
All of this is true today. When any of it changes, this page changes with it.
- Encryption
- TLS 1.3 in transit. AES-256 at rest for the database and backups.
- Authentication
- Email + password on every tier, with verified addresses and one-time reset links. SSO on Business.
- Sub-processors
- Resend and Automattic (Gravatar). Full list with DPAs on request.
- GDPR & DPA
- Standard DPA on request. Because we never receive policy contents, the data-processor footprint is small.
- Data retention
- Audit-log entries retained for 90 days (Free), 2 years (Pro), or unlimited (Business). Deletion is permanent: no soft-delete, no shadow copy.
- Penetration testing
- Annual third-party pen-test. Reports available under NDA.
Disclosure
Found something? Tell us.
Email [email protected] and we will answer within one business day.