Made with AISecurity and privacy in Lyyli.ai: a technical overview for IT teams
Mikko Oksanen
CEO & Co-founder
Summary
- Lyyli is a communications operations system: needs, plans, drafts and approvals in one workspace.
This overview is for IT, privacy and security teams. It describes the current state as documented in the Trust Center and product pages. Binding terms are always in Legal; public claims are in the Trust Center.
011. What Lyyli is
Lyyli.ai is a communications operations system. It helps identify communication needs, turn them into plans and tasks, produce organisation-context channel versions, and manage comments, versions and approvals in one workspace. Approved content is taken to the destination platform for publishing.
022. Publishing and integrations
There are no direct channel publishing APIs. Integrations are described by capability:
- Slack: monitoring selected channels to identify communication needs (no direct publishing).
- Meeting Agent: joins Google Meet, Microsoft Teams and Zoom meetings.
- Teams Idea Collector: on the roadmap.
- LinkedIn and other channels: content is prepared and approved in Lyyli; publishing happens on the destination platform.
- Email: handling inbound briefs or communication needs.
033. Data location
Primary application data for customer workspaces is stored in the EU. Language-model inference goes through Vercel AI Gateway: Claude and Gemini in the EU, GPT globally for now. Authentication, email delivery, analytics and other subprocessor functions may occur outside the EU/EEA under documented transfer mechanisms. Current vendors: vendor register.
044. AI routes and ZDR
Language-model requests go through Vercel AI Gateway (Anthropic Claude, Google Vertex AI Gemini, OpenAI GPT). Models process requests under Zero Data Retention: the model provider does not retain the prompt or response after the request. Lyyli stores conversations in its own EU environment to deliver the service. Claude and Gemini inference is locked to the EU; GPT processing cannot currently be limited to the EU only. ZDR does not cover Lyyli's own conversation history storage, image generation, web search, meeting recordings, or abuse-monitoring logs. There are no ZDR exceptions in the current language-model lineup. Row-level detail: AI model register.
055. Roles and access
The product role model is Admin and Member. External review links allow commenting without a user account in documented scope. Customers manage shared-link access.
066. Audit trail
On Professional, approval events and key content actions are recorded in the audit trail in documented scope (for example user, action, state and timestamp). We do not claim forever retention of every change, or that Lyyli blocks publishing on an external channel.
077. Meeting Agent and recordings
Meeting Agent joins via a bot and notifies participants about transcription. Customers are responsible for informing participants and defining the legal basis. Retention is described in the retention annex; some values remain under verification and are marked as draft.
088. Certifications
Lyyli is not currently ISO 27001 certified. We develop ISMS practices using that framework as a reference. Subprocessor certifications do not automatically extend to the Lyyli product.
099. Where to verify current facts
For privacy or security questions, contact us at hello@lyyli.ai. For a technical Q&A before procurement, book a demo.
Want to see Lyyli in one of your processes?
Book a demo. We walk through one of your communications workflows from need to approval.
- •Communications operations in practice
- •Publishing without channel APIs
- •Trust Center and documented AI routes
- •Starter, Growth and Professional plans
The service is currently available to new organisations by invitation only.




