LeanOS
Home
Trust Center

Everything procurement asks for, in one place.

Last updated: 17 May 2026

LeanOS is a B2B SaaS platform that holds defect photos, kaizen savings, A3 cases, and other operational data that may include trade secrets. We treat your data the way you would.

Real-time status
All services operational
Live page →status.getleanos.com

Real-time uptime + incident history powered by Better Stack. Subscribe via email or webhook to get notified the moment anything degrades. Linked from every runbook in our ops response chain.

Verify these yourself

We don’t expect you to take our word for anything. Every link below runs an independent third-party scan against getleanos.com — no LeanOS involvement required.

Public documents

Operational runbooks

The procedures we follow during incidents, backups, and recovery. Each card opens the customer-facing commitments (what we’d sign into the MSA / DPA anyway). The full playbook is pre-prepared and available under NDA — typical turnaround 3 business days.

Available on request — email founder@getleanos.com

We respond to security and contract diligence requests within 3 business days.

Master Services Agreement (MSA)

Our standard MSA template for paid Pro / Enterprise subscriptions. Customer-redlines reviewed case-by-case.

Request via email
Pilot Agreement

Our standard 30-day free Pilot Agreement. Suitable for evaluation in one plant, up to 25 seats.

Request via email
Data Processing Agreement (DPA)

DPDP Act + GDPR-aware DPA covering processing roles, security measures (Annex B), subprocessors (Annex C), cross-border transfer mechanisms.

Request via email
Mutual NDA

Mutual confidentiality agreement for pre-contract diligence sessions.

Request via email
Order Form template

Pricing + scope template for Pro / Enterprise subscriptions. Annual prepaid; auto-renewing.

Request via email
Vendor information sheet

Our company information, GST, PAN, bank details, and tax info for your vendor master / procurement system.

Request via email
Security questionnaire response (CAIQ / SIG-Lite / custom)

Pre-filled answers to 50+ standard security questions covering architecture, access control, incident response, AI use, third-party risk, and compliance.

Request via email
Architecture brief

Detailed technical architecture overview: authentication, RLS isolation, encryption, backup, audit logging, AI use, subprocessors, incident response.

Request via email
Independent audit reports — when ready

SOC 2 Type I — initiated upon enterprise contract signature. SOC 2 Type II + ISO 27001 on roadmap.

Request via email

Things we explicitly don't do

  • No advertising or marketing tracking. No Google Ads, Meta Pixel, LinkedIn Insight Tag, behavioural analytics (GA, Mixpanel, etc.).
  • No Customer Data for AI training. Anthropic does not train on API data; we do not train any in-house model on Customer Data.
  • No data enrichment against third-party data brokers (Clearbit, ZoomInfo, etc.).
  • No automatic actions on AI output. Every AI suggestion requires human review by an authorized Customer user before any action.
  • No marketing use of Customer defect photos without separate, photo-by-photo, written consent.
  • No pre-filled cookie consent. We use only strictly-necessary authentication cookies; no banner needed because we don't set any non-essential cookies.

Inbound security or contract review?

Email founder@getleanos.com with the subject “Security review” or “Contract review” and your typical procurement turnaround. We respond within 3 business days with the relevant documents and an offer to schedule a 30-minute architecture / contract Q&A call with the founder.