Ligo Launch handles contractor businesses' livelihoods — job records, customer data, payment flows, and communications. We take that responsibility seriously. This page describes the technical and operational controls we have in place to protect your data and your customers' data.
All connections to Ligo Launch — from the web app, the Ava mobile app, or any API client — are encrypted using TLS 1.2 or higher. This is enforced at the Cloudflare network layer, which terminates connections and forwards traffic internally over encrypted tunnels.
Sensitive data stored in our systems is protected at rest using AES-256 encryption, the same standard used by major financial institutions.
Ligo Launch uses phone number + one-time passcode (OTP) as the primary login method. A 6-digit code is sent to your registered phone number via SMS and expires in a short window. No password is stored or transmitted — you cannot be phished for a password that doesn't exist.
The Ava mobile app supports Face ID and Touch ID (device biometrics) as an optional login method after your first session. Biometric data is processed entirely within Apple's Secure Enclave and is never transmitted to or accessible by Ligo Launch.
Sessions are issued as signed tokens with a finite expiry. Tokens are rotated on re-authentication. Revoking access — for any reason — instantly invalidates all active sessions for that account across all devices.
The Ligo platform enforces role-based access control across all internal surfaces. Each team member or system component is granted the minimum permissions necessary to perform their function — the principle of least privilege.
Access controls are enforced at the database layer, not just at the API layer. Even if an application-level bug attempted to return data outside a user's scope, the database enforces isolation and rejects the query. Contractor data cannot bleed across accounts.
All card payments are processed by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of payment card industry certification. Ligo Launch never sees, stores, or logs your card number, CVV, or full card data. Card details are entered directly into Stripe's secure hosted fields and never touch our servers.
Business bank account connections for bookkeeping features are handled through Plaid, a regulated financial data network. Plaid manages the bank authentication flow and provides us with read-only access tokens — we never receive or store your banking credentials.
You can disconnect your bank connection at any time from account settings, which revokes access immediately.
Photos, contracts, documents, and other files you upload are stored in Cloudflare R2 under private access policies. Files are not publicly accessible by default.
When the platform needs to display or share a private file, it generates a signed, time-limited URL — a URL that includes a cryptographic signature and an expiry timestamp. The signature is verified by Cloudflare before serving the file. Once the URL expires, it returns a 403 error even if someone has a copy of the link.
We retain your account data for as long as your account is active. After account cancellation, we retain data for up to 90 days to allow reactivation or export, after which it is permanently deleted.
The following categories of high-sensitivity temporary data are automatically purged on a shorter schedule:
You can request deletion of your account and all associated data at any time by emailing support@ligolaunch.com. We will process deletion requests within 30 days. Certain records may be retained longer as required by law (e.g., billing records for tax compliance).
We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue in any Ligo Launch system — the web app, the Ava mobile app, our API, or any public-facing service — please report it to us privately before publishing or exploiting it.
Send a description of the issue to support@ligolaunch.com with the subject line "Security Disclosure." Include:
In-scope surfaces include ligolaunch.com, ava.ligolaunch.com, admin.ligolaunch.com, the Ava iOS/Android app, and any API endpoint under those domains. Please do not test against real user accounts or data that does not belong to you.
Security questions, vulnerability reports, data deletion requests, or general trust and safety inquiries:
Ligo Network LLC d/b/a Ligo LaunchFor general privacy requests, see our Privacy Policy. For terms of use, see our Terms of Service.