Trust & Security

Security at Ligo Launch

Ligo Network LLC d/b/a Ligo Launch  ·  Last updated June 12, 2026

🔒
TLS 1.2+ in Transit
All traffic encrypted end-to-end via Cloudflare
🛡️
AES-256 at Rest
Sensitive data and auth tokens encrypted at the storage layer
🔑
No Stored Passwords
Login uses one-time codes — no password to steal or leak
💳
Stripe PCI
We never see or store your card number
🔐
RBAC
Least-privilege internal access controls
⏱️
Expiring URLs
Signed, time-limited access to private files
On this page
  1. Our Security Approach
  2. Encryption in Transit
  3. Encryption at Rest
  4. Authentication and Identity
  5. Access Controls
  6. Payment and Banking Security
  7. Private Media and File Access
  8. Data Retention and Automated Expiry
  9. Vulnerability Disclosure
  10. Contact

01 Our Security Approach

Ligo Launch handles contractor businesses' livelihoods — job records, customer data, payment flows, and communications. We take that responsibility seriously. This page describes the technical and operational controls we have in place to protect your data and your customers' data.

Questions or issues? Email support@ligolaunch.com — we take security reports seriously and respond within 1 business day.

02 Encryption in Transit

All connections to Ligo Launch — from the web app, the Ava mobile app, or any API client — are encrypted using TLS 1.2 or higher. This is enforced at the Cloudflare network layer, which terminates connections and forwards traffic internally over encrypted tunnels.

03 Encryption at Rest

Sensitive data stored in our systems is protected at rest using AES-256 encryption, the same standard used by major financial institutions.

04 Authentication and Identity

Primary Login — Phone One-Time Code

Ligo Launch uses phone number + one-time passcode (OTP) as the primary login method. A 6-digit code is sent to your registered phone number via SMS and expires in a short window. No password is stored or transmitted — you cannot be phished for a password that doesn't exist.

Biometric Authentication

The Ava mobile app supports Face ID and Touch ID (device biometrics) as an optional login method after your first session. Biometric data is processed entirely within Apple's Secure Enclave and is never transmitted to or accessible by Ligo Launch.

Session Management

Sessions are issued as signed tokens with a finite expiry. Tokens are rotated on re-authentication. Revoking access — for any reason — instantly invalidates all active sessions for that account across all devices.

05 Access Controls

Role-Based Access (RBAC)

The Ligo platform enforces role-based access control across all internal surfaces. Each team member or system component is granted the minimum permissions necessary to perform their function — the principle of least privilege.

Database-Layer Isolation

Access controls are enforced at the database layer, not just at the API layer. Even if an application-level bug attempted to return data outside a user's scope, the database enforces isolation and rejects the query. Contractor data cannot bleed across accounts.

06 Payment and Banking Security

Stripe — Card Payments

All card payments are processed by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of payment card industry certification. Ligo Launch never sees, stores, or logs your card number, CVV, or full card data. Card details are entered directly into Stripe's secure hosted fields and never touch our servers.

Bank Account Connections

Business bank account connections for bookkeeping features are handled through Plaid, a regulated financial data network. Plaid manages the bank authentication flow and provides us with read-only access tokens — we never receive or store your banking credentials.

You can disconnect your bank connection at any time from account settings, which revokes access immediately.

07 Private Media and File Access

Photos, contracts, documents, and other files you upload are stored in Cloudflare R2 under private access policies. Files are not publicly accessible by default.

When the platform needs to display or share a private file, it generates a signed, time-limited URL — a URL that includes a cryptographic signature and an expiry timestamp. The signature is verified by Cloudflare before serving the file. Once the URL expires, it returns a 403 error even if someone has a copy of the link.

08 Data Retention and Automated Expiry

We retain your account data for as long as your account is active. After account cancellation, we retain data for up to 90 days to allow reactivation or export, after which it is permanently deleted.

The following categories of high-sensitivity temporary data are automatically purged on a shorter schedule:

You can request deletion of your account and all associated data at any time by emailing support@ligolaunch.com. We will process deletion requests within 30 days. Certain records may be retained longer as required by law (e.g., billing records for tax compliance).

Data portability: On request, we will provide a copy of your account data in a portable format before deletion. Contact support@ligolaunch.com to initiate a data export.

09 Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue in any Ligo Launch system — the web app, the Ava mobile app, our API, or any public-facing service — please report it to us privately before publishing or exploiting it.

How to Report

Send a description of the issue to support@ligolaunch.com with the subject line "Security Disclosure." Include:

What to Expect

Scope

In-scope surfaces include ligolaunch.com, ava.ligolaunch.com, admin.ligolaunch.com, the Ava iOS/Android app, and any API endpoint under those domains. Please do not test against real user accounts or data that does not belong to you.

10 Contact

Security questions, vulnerability reports, data deletion requests, or general trust and safety inquiries:

Ligo Network LLC d/b/a Ligo Launch
Attn: Security
322 N Shore Drive, Bldg 1B, Suite 200
Pittsburgh, PA 15212
support@ligolaunch.com

For general privacy requests, see our Privacy Policy. For terms of use, see our Terms of Service.