Skip to main content

Security & Transparency

Trust Center

Lumis is built for high-stakes compliance. We prioritize security and transparency so you can focus on building your fintech.

Security Overview

Our multi-layered security model ensures your data remains isolated, immutable, and protected.

Multi-Tenant Isolation

Every query enforces workspaceId ownership. Cross-tenant data access is impossible at the database layer.

Tamper-Evident Logs

Audit logs are cryptographically sealed with SHA-256 hash-chaining to ensure non-repudiation.

PII Masking

Sensitive data is scrubbed before it ever hits our database, reducing your compliance surface area.

MFA Step-up Auth

Email-based OTP verification required before performing sensitive actions like generating API keys.

Sub-processors

We maintain a transparent list of companies that process data on our behalf. Sub-processor changes are announced 30 days in advance.

ProcessorPurposeLocationSecurity
ConvexApplication database and backend computeAWS eu-west-1 (Ireland, Europe)View
CloudflareHosting (CDN, Edge runtime) and static assetsGlobal EdgeView
Lemon SqueezyPayment processing and billing managementUSAView
ResendTransactional emailUSAView

Data Retention

Data is retained based on your workspace tier. After the retention window, records are automatically and permanently purged.

TierAudit Log RetentionPrimary Use Case
Free7 daysTesting & Sandboxing
Pro90 daysEarly-stage compliance
Business1 yearMid-market audits

Global Data Processing:While all sandbox mock-data is processed globally via Cloudflare's Edge to ensure sub-500ms latency, persistent data is physically stored in AWS (Ireland) to natively satisfy strict GDPR Data Residency requirements.

Operational Resilience

We maintain high availability for our compliance engine through geographically distributed edge nodes and redundant database clusters.

System Status & Uptime

Our target uptime for the simulation engine is 99.9%.

View Live Status Page

Compliance Status

A real-time dashboard of our security controls and independent audit progress.

Row-level security (workspace isolation)

Enforced in Convex functions + RBAC middleware

In Place
Tamper-evident audit logs (Hash-chaining)

Cryptographic SHA-256 seals computed daily

In Place
PII masking in audit logs

Redaction of email, SSN, and phone numbers

In Place
MFA Step-up Authentication

OTP verification required for sensitive actions like API keys

In Place
SAST in CI (Semgrep)

Automated code analysis on every push

In Place
Dependency scanning (pnpm audit)

CI fails on High+ vulnerability CVEs

In Place
SAML 2.0 / Enterprise SSO

Integration with Okta/Azure AD in progress

Planned
SOC 2 Type I report

Building evidence foundation; target Q4 2026

Planned
EU Data Residency

All data is natively stored in Europe (Ireland)

In Place

Responsible Disclosure

We value the work of security researchers. If you discover a vulnerability, please report it to us immediately so we can protect our users.

How to report

  • 1.Email details to security@lumiscompliance.com
  • 2.Include steps to reproduce and impact
  • 3.Allow us 48 hours to acknowledge
  • 4.Do not disclose publicly until fixed

Our Commitment

We will not take legal action against researchers who discover vulnerabilities in good faith and follow our disclosure process. We will credit you in our release notes for confirmed patches.

Have security questions?

Our security team is ready to help you with questionnaires, DDQs, or deeper technical reviews.

Contact Security Team