Trust & Security

This page is maintained by the Lumaye team to answer common security, privacy, and compliance questions. It describes controls in place today. It is not an independent audit or certification.

Compliance posture

Lumaye is built on infrastructure that is SOC 2 Type II attested and ISO 27001-aligned. Our processing is designed to meet the requirements of the EU GDPR, the UK GDPR, and equivalent frameworks worldwide. We can execute a Data Processing Addendum (DPA) with Standard Contractual Clauses on request.

We do not claim any certification we have not obtained. Enterprise buyers can request our current security package including SOC 2 report, subprocessor list, and pentest summary under NDA.

Encryption & keys

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Backups are encrypted with the same standard. Application secrets and API keys are stored hashed; raw tokens are shown to administrators exactly once at creation and never persisted in plaintext.

Data residency

Organizations choose a data region (Global, US, EU, APAC, LATAM, MEA) at onboarding. Primary storage for that org's documents and generated embeddings is kept within the chosen region. Cross-region access is limited to authenticated org members.

Access control & SSO

Every write and read is scoped by row-level security to the organization and, where applicable, the manufacturing site. Enterprise customers can enable SAML SSO (Okta, Azure AD / Entra ID, OneLogin) with domain-based auto-provisioning. Role-based access includes plant, production, maintenance, quality, safety, contractor, auditor, and executive tiers.

Privacy & subprocessors

We process only the data your organization uploads or generates while using Lumaye. Copilots and generated answers stay inside your org. We use a small set of subprocessors — cloud hosting, transactional email, and model providers — enumerated in our current subprocessor list, available on request.

Retention & deletion

Documents, chat history, and work-order records are retained for the lifetime of your subscription. Admins can delete individual records at any time. On account closure, all customer data is deleted within 30 days, with backups purged on the standard rotation.

Public API

The Lumaye REST API is available at /api/public/v1 with per-org API keys, scoped to documents:read, workorders:read, and chunks:read. Tokens are sent as Authorization: Bearer <token>. Keys can be revoked at any time from Settings → API keys.

Incident response & disclosure

We monitor infrastructure and application logs continuously. If we confirm a security incident affecting your data, we will notify your organization's administrators without undue delay and provide a written summary. Report a suspected vulnerability to security@lumaye.com. We do not take legal action against good-faith researchers who follow responsible disclosure.

Last updated July 30, 2026. Questions? security@lumaye.com.