Security & Transparency
Trust Center
Lumis is built for high-stakes compliance. We prioritize security and transparency so you can focus on building your fintech.
Security Overview
Our multi-layered security model ensures your data remains isolated, immutable, and protected.
Multi-Tenant Isolation
Every query enforces workspaceId ownership. Cross-tenant data access is impossible at the database layer.
Tamper-Evident Logs
Audit logs are cryptographically sealed with SHA-256 hash-chaining to ensure non-repudiation.
PII Masking
Sensitive data is scrubbed before it ever hits our database, reducing your compliance surface area.
MFA Step-up Auth
Email-based OTP verification required before performing sensitive actions like generating API keys.
Sub-processors
We maintain a transparent list of companies that process data on our behalf. Sub-processor changes are announced 30 days in advance.
Data Retention
Data is retained based on your workspace tier. After the retention window, records are automatically and permanently purged.
| Tier | Audit Log Retention | Primary Use Case |
|---|---|---|
| Free | 7 days | Testing & Sandboxing |
| Pro | 90 days | Early-stage compliance |
| Business | 1 year | Mid-market audits |
Global Data Processing:While all sandbox mock-data is processed globally via Cloudflare's Edge to ensure sub-500ms latency, persistent data is physically stored in AWS (Ireland) to natively satisfy strict GDPR Data Residency requirements.
Operational Resilience
We maintain high availability for our compliance engine through geographically distributed edge nodes and redundant database clusters.
System Status & Uptime
Our target uptime for the simulation engine is 99.9%.
Compliance Status
A real-time dashboard of our security controls and independent audit progress.
Enforced in Convex functions + RBAC middleware
Cryptographic SHA-256 seals computed daily
Redaction of email, SSN, and phone numbers
OTP verification required for sensitive actions like API keys
Automated code analysis on every push
CI fails on High+ vulnerability CVEs
Integration with Okta/Azure AD in progress
Building evidence foundation; target Q4 2026
All data is natively stored in Europe (Ireland)
Responsible Disclosure
We value the work of security researchers. If you discover a vulnerability, please report it to us immediately so we can protect our users.
How to report
- 1.Email details to security@lumiscompliance.com
- 2.Include steps to reproduce and impact
- 3.Allow us 48 hours to acknowledge
- 4.Do not disclose publicly until fixed
Our Commitment
We will not take legal action against researchers who discover vulnerabilities in good faith and follow our disclosure process. We will credit you in our release notes for confirmed patches.
Have security questions?
Our security team is ready to help you with questionnaires, DDQs, or deeper technical reviews.
Contact Security Team