For your vendor review

Security overview

How I build and operate client systems, written for the IT and security people who have to approve me. Short and specific.

Vendor
Lobi Software Studio
Contact
Ben Johnson, founder
Version
1.0
Last updated
September 26, 2026

1.Where systems run

In your environment, not mine. Everything I build is deployed to cloud accounts your organization owns and pays for.

  • Hosting: your AWS, Azure, or Google Cloud account.
  • Source code: your repository, from the first commit.
  • Infrastructure: defined in code and reviewed like code, so every change has a history and a reviewer.

2.Access

I work through access you grant, and you can remove it in one step.

  • Sign-in through your identity provider, with multi-factor authentication.
  • Roles scoped to the work at hand. Production access only when a task needs it.
  • Every access is logged in systems you control.

My own machines are Apple devices with biometric sign-in, full-disk encryption, and automatic screen lock.

3.Data handling

Production data stays in your environment. I don't copy it to my machines or to any system I operate.

  • Development and testing use synthetic or de-identified data.
  • Sensitive fields can be encrypted per client while staying searchable.
  • Audit events are chained together, so an edited or deleted record shows.

4.Change management

Nothing reaches production without a record.

  • Every change goes through a pull request in your repository.
  • Automated tests run before anything merges.
  • Deploys run from your pipeline, so the history of what shipped, and when, lives with you.

5.AI and outside services

You decide which outside services see your data, and every call is on record.

  • Each AI or data provider is listed and approved by you before it's used.
  • Every outside call leaves a receipt: what was sent, for which records, and what came back.
  • Documents the system reads are wrapped in a marker that changes every time, so text hidden inside a file can't pose as an instruction.
  • Where the evidence doesn't support an answer, AI features are built to decline rather than guess.

6.Support and incidents

Clients on the Run and Build plans get outage response and security upkeep. That covers monitoring, patches, dependency updates, and verified backups.

Response expectations are written into each plan agreement, not promised on a web page.

7.Offboarding

Ending the relationship takes one step: remove my access. The code, data, documentation, and runbooks are already in your accounts, so there is nothing to hand back.

8.Compliance

Built to SOC 2 principles. Systems run inside your environment, under your controls, so they fit the audits and policies you already have.

Business associate agreements signed for any work that touches PHI.

One person with access. You'll always know who it is, because it's me.

Need this for your vendor file?

I'll send a PDF of this overview and answer your security questionnaire directly.