Website and inquiry controls
The public site is hosted on Vercel. Inquiry forms are processed by server-side routes before accepted data is forwarded to managed Google Workspace systems for review and follow-up.
HTTPS and HSTS on the production domain.
Server-side field validation, origin checks, spam traps, and input length limits.
Server-side webhook delivery keeps receiver credentials out of the browser.
Security headers restrict framing, content sniffing, referrers, and unused browser permissions.
Validated requests enter access-controlled Google Workspace sheets and internal email alerts.
Inquiry data path
- Your browser sends the form to the TLG Labs production domain.
- The server validates, sanitizes, and screens the request.
- Accepted fields are sent through an authenticated webhook to a restricted lead sheet and internal alert.
- The TLG Labs team reviews the request and follows up directly.
Product security is evaluated product by product
TLG Labs products do not all use the same hosting, integration, data, or AI architecture. We do not use this page to imply a blanket certification or control set across every app. During evaluation, we document the architecture and operating boundaries relevant to the selected product, pilot, and customer environment.
Where AI is used, the evaluation should identify the provider, permitted data, source grounding, output review, action boundaries, and fallback path before production use.
What an enterprise buyer can request
- Product-specific data flow and integration scope
- Authentication, permission, and user-role assumptions
- Data categories, storage, retention, and deletion expectations
- AI provider, model, grounding, and human-review boundaries when applicable
- Pilot scope, support ownership, incident path, and production hardening plan
Report a security concern
Send a concise description, affected URL or product, reproduction steps, and potential impact through the TLG Labs contact form or to info@thelodestonegroup.com. Please do not include customer data or exploit a vulnerability beyond what is necessary to demonstrate the issue.