Trust center
How Lumi and Lumi Cloud handle your code, prompts and data, and where each security document stands.
Draft. Luminary hasn't reviewed this page yet, and nothing on it has been independently audited or tested.
Documents
| Document | Status | What it is |
|---|---|---|
| Data Processing Addendum | Draft | GDPR Article 28 processor terms written from Lumi Cloud's data model; with counsel for review. |
| Subprocessors | Draft | The outside services the code talks to and what each receives; none is contracted yet because Lumi Cloud isn't hosted yet. |
| Security questionnaire answers | Draft | Common questions (CAIQ and SIG Lite style), answered from the code. Download below. |
| Independent penetration test | Planned | Scoped, not yet performed. A summary letter will be published here after the test and retest. |
| SOC 2 Type I | Not started | Controls are being mapped to the Trust Services Criteria; no audit has been engaged, and Lumi Cloud holds no SOC 2 report. |
| SOC 2 Type II | Not started | Follows a Type I after a 3 to 12 month observation period. The plan for the evidence each control must leave is drafted. |
| ISO/IEC 27001 | Not started | A readiness review and a draft Statement of Applicability for the 93 Annex A controls. No certification body is engaged, and Luminary holds no certificate. |
| HIPAA business associate agreement | Draft | Drafted and with counsel; not offered yet. By design Lumi Cloud doesn't receive prompts or code unless an organization turns on oversight of its own members' messages, and an organization can turn off conversation copies. |
| Accessibility conformance report (VPAT) | Draft | A self-assessed WCAG 2.1 A and AA report for the app and the portal, in the VPAT 2.5 format. Not independently audited, and not yet tested with screen readers. |
| Support and service levels | Draft | Support tiers, severity levels and first-response targets; with counsel for review, and not a commitment until an order form includes them. |
Lumi Cloud holds no certification today. Ask your Luminary contact for documents marked draft; they're shared only after review.
Where your code and prompts go
- Lumi runs on your computers and sends prompts to the model providers your organization chooses, with your own keys or your own gateway. Lumi Cloud isn't in that path.
- Model keys stay in each computer's credential store (Windows Credential Manager, the macOS Keychain or the system keyring), never in Lumi Cloud.
- Lumi Cloud stores people, organizations, devices, policy, and usage and cost totals the app reports. It stores conversation text only when someone chooses to share a session or hand off work, after the app removes saved keys and secret-looking values, approved team notes and library items, and the support requests people write to Luminary.
- Organization oversight is off unless an organization turns it on for its own members. Then each member's Lumi shows them a notice and sends nothing to a model until they confirm it; the computer signs the confirmation, and Lumi Cloud keeps it as the record they were told. Runs with nobody at the computer, such as scheduled tasks, print the notice in their log and are recorded under the computer's user, or are refused, as the organization chooses. Lumi sends the organization's Lumi Cloud what the policy asks for: activity, optionally messages and session titles without secrets, and security flags. Messages and titles are encrypted under the organization's data key, kept for the organization's retention period, readable only by its owners, security admins, auditors and admins an owner allows, and every reading is recorded.
Control on every computer
- Organization policy is signed with the organization's Ed25519 key; the app refuses a policy it can't verify, and a machine policy set by IT outranks everything else.
- Policy can limit models and providers, require zero data retention, lock settings, exclude files from the agent, hold risky commands for a second person's approval, and require signed or registry-approved extensions.
- The app keeps a hash-chained audit log on each computer, with optional OpenTelemetry export.
Identity and access
- Single sign-on with OpenID Connect, or SAML through WorkOS, on verified domains, with enforcement; SCIM 2.0 provisioning, where deprovisioning suspends access at once.
- Two-step verification (TOTP) for the portal, which an organization can require for every role but member, and portal session limits.
- Roles: owner, admin, security admin, billing admin, auditor and member; pages check permissions, not roles.
How it's built
- Every change runs the test suites in CI before it merges; releases are built by CI and the update feed is signed.
- Portal sessions, invitations, sign-in links and API tokens are stored only as SHA-256 hashes; signing keys and integration credentials are encrypted with the service's master key.
- What people send (conversation copies, the library, support requests) is encrypted under each organization's data key, which it can protect with its own key in AWS KMS, Google Cloud KMS or Azure Key Vault (a first pass, not yet tried against those services).
- Strict Content Security Policy, no framing, HSTS over https, CSRF tokens and origin checks on every form.
Not decided or not built yet
- Lumi Cloud isn't hosted yet, so hosting region, database encryption at rest, backups and uptime commitments aren't decided.
- There's no independent penetration test or SOC 2 report yet (see the status above).
Security questionnaire
Answers to common vendor-review questions, each grounded in the code. Download them as CSV to import into your review tool.
Read the 28 answers here
- DSP-01 · Data security
Does Lumi Cloud store customer source code? - No. Code stays on the customer's computers. The app sends file contents only to the model provider the organization chose.
- DSP-02 · Data security
Does Lumi Cloud store prompts or model responses? - Only when a person chooses to share a session or hand off work: then it keeps a read-only copy of the messages and replies, without tool output, after the app removes saved keys and secret-looking values. The person can stop sharing.
- DSP-03 · Data security
Where are model provider API keys stored? - In each computer's operating-system credential store. They're never sent to Lumi Cloud and are removed from what the agent's tools see.
- DSP-04 · Data security
Is data encrypted in transit? - Yes. The portal and APIs are served over https with HSTS, and the app talks to Lumi Cloud over https. It reaches model providers over https too, except local or private-network endpoints an organization configures, such as Ollama, which may use http.
- DSP-05 · Data security
Is data encrypted at rest? - Content people send (shared sessions, hand-offs, the library, requests from chat, commands for approval, support requests and review titles), and the messages, session titles, flag excerpts and signed notice acknowledgments organization oversight receives, are encrypted with AES-256-GCM under a data key per organization. Signing keys, SSO client secrets, TOTP keys and integration credentials are encrypted with the service's master key (Fernet). Whole-database encryption depends on hosting, which isn't chosen yet.
- DSP-09 · Data security
Can we manage the encryption keys (customer-managed keys)? - A first pass: an organization's data keys can be wrapped by its own key in AWS KMS, Google Cloud KMS or Azure Key Vault. After that key is revoked, Lumi Cloud can read the content it protects only until unwrapped data keys leave its memory (5 minutes by default), and it can't move the content to another key without the key answering. The activity log, email and chat messages aren't covered. Lumi Cloud uses one identity for every customer's key for now. It hasn't been tested against those services yet, only against stand-ins.
- DSP-06 · Data security
What does the app report to Lumi Cloud? - App version, the policy version applied, usage and cost totals per model, and counts of task outcomes. Never prompts, code, file paths or session titles, unless the organization turns on oversight: then, after each member confirms a notice (a confirmation the computer signs), each turn's activity (with the project folder's name, or its path if the organization asks, what started it and the computer's user) and security flags; session titles and the paths tools were given only with messages, which are optional and have secrets removed. Runs with nobody at the computer are recorded under the computer's user, or refused, as the organization chooses. File contents and tool output never leave the computer.
- DSP-07 · Data security
Can an organization require zero data retention by model providers? - Yes. Policy can allow only local models, connections marked as keeping no data, and providers the organization has an agreement with.
- DSP-08 · Data security
Can files be kept away from the agent? - Yes. Policy and project settings exclude files by pattern; excluded files aren't read, listed or sent.
- IAM-01 · Identity and access
Is single sign-on supported? - Yes, on domains the organization verifies with DNS, and it can be enforced.
- IAM-02 · Identity and access
Which single sign-on protocols are supported? - OpenID Connect directly, and SAML through WorkOS when the service is set up with it.
- IAM-03 · Identity and access
Is multi-factor authentication supported and enforceable? - Yes, TOTP two-step verification with single-use recovery codes; an organization can require it for every role but member. Single sign-on counts as the second step.
- IAM-04 · Identity and access
Is user provisioning automated? - Yes, SCIM 2.0 for users and groups. Deactivating a user ends their portal sessions, desktop sign-ins and devices at once.
- IAM-05 · Identity and access
Is access role-based? - Yes: owner, admin, security admin, billing admin, auditor and member, checked per permission.
- IAM-06 · Identity and access
Can sessions be limited and revoked? - Yes. Portal sessions can end 8 hours to 7 days after sign-in, and administrators can sign someone out of every portal session and desktop sign-in at once.
- LOG-01 · Logging and monitoring
Are administrative actions logged? - Yes. Portal actions are recorded, searchable and exportable (CSV, JSON Lines), and can be delivered to Splunk, Datadog or a signed webhook.
- LOG-02 · Logging and monitoring
Is activity on the desktop logged? - Yes. Each computer keeps a hash-chained audit log of agent activity, with optional OpenTelemetry export.
- CHG-01 · Change management
How are changes reviewed and tested? - Through pull requests; CI runs the test suites and builds before a merge. Releases are built in CI.
- CHG-02 · Change management
How are updates delivered and verified? - Through a signed update feed (EdDSA); IT can pin a version or turn updates off by policy.
- AGT-01 · AI agent controls
Can the agent run commands without approval? - Only in modes the person (or policy) allows. Deny rules always apply, irreversible actions such as force-pushing to a main branch are refused, and policy can require a second person's approval for commands it names.
- AGT-02 · AI agent controls
Can agent changes merge without human review? - Policy can stop the agent from merging or pushing to default branches and send its pull requests to named reviewers.
- AGT-03 · AI agent controls
How are third-party extensions controlled? - Nothing in a capability pack runs until a person approves exactly its files. Policy can limit packs by id and source, require publisher signatures, or allow only the organization's registry at pinned versions.
- VUL-01 · Vulnerability management
Has an independent penetration test been performed? - Not yet. It's scoped, and a summary will be published after the test and retest.
- CMP-01 · Compliance
Do you have a SOC 2 report? - No. Controls are being mapped to the Trust Services Criteria; no audit has been engaged.
- CMP-02 · Compliance
Will you sign a DPA? - A Data Processing Addendum is drafted and with counsel; it isn't offered yet.
- CMP-03 · Compliance
Do you hold an ISO 27001 certificate? - No. A readiness review and a draft Statement of Applicability exist; no certification body is engaged.
- CMP-04 · Compliance
Will you sign a HIPAA business associate agreement? - Not yet: a BAA is drafted and with counsel. Lumi Cloud doesn't receive prompts or code by default; shared sessions, hand-offs and organization oversight's messages could carry conversation text. An organization can turn copies off and keep oversight's messages off so it never arrives.
- BCP-01 · Business continuity
What are your backup and recovery commitments? - Not decided: Lumi Cloud isn't hosted yet. While it's unreachable, the desktop app keeps working and keeps enforcing its last verified policy until that expires (14 days, plus 7 days' grace).