Product
Security & data, stated plainly.
Lecron is in early access, onboarding its first labs in small batches. This page says where things stand today rather than describing a posture we have not built yet, including the parts that are not finished.
Updated September 18, 2026
Where things stand today
The demo is invitation-only
Access is controlled by an email allow list: the address you sign in with decides whether you are on it. Every case, patient, dentist and laboratory inside the demo is fictitious.
No advertising trackers, anywhere
Not on this site and not in the demo. What the public site runs is PostHog, counting page views and clicks on the handful of buttons that lead to a tour or a call. No advertising identifiers, and no session replay here.
Your contact details are not a product
We do not sell or rent them, and we do not contact you about anything other than Lecron and your early access.
HIPAA and business associate agreements
We are working this through, and it is not finished. We will not tell you Lecron is covered before it is. A lab that takes that claim at face value and is wrong has a much bigger problem than a missing feature.
What that means in practice: before any real patient case goes into Lecron, we agree in writing with your lab what we hold, where it sits and what happens to it. If you need to know exactly where that work has got to before you can take a demo, ask us and we will tell you straight: [email protected].
Where the data sits
This site and the demo are served by Cloudflare. Every connection to either is encrypted in transit, and the services that hold anything for us (the newsletter list, the usage records from the demo) encrypt it at rest. Production access is held by the two founders and nobody else.
The booking page loads Cal.com, an independent scheduling service, so you can pick a time; what you enter there is handled by Cal.com to arrange the call and nothing else. Every service that handles your information on our behalf is named on the sub-processors page, with what it handles and where it runs.
The full detail of what this site collects, why, and how to have it removed is on the privacy page, which is written to be read rather than skimmed past.
Report a security issue
If you find a weakness in this site or the demo, write to [email protected]. Say what you found and how to reproduce it. A founder reads that inbox, replies within two business days, and tells you what we did about it. Please test against the demo only: it holds no real person's data, and nothing else of ours should be touched.
Ask us the hard question.
The security conversation is easier with a person than a web page. Request a demo and bring it up first. We would rather answer it early than late.