Legal

Security

How we protect your data and maintain the security of our platform.

Last updated:February 1, 2025

Our Commitment

Security is at the core of everything we do at Lumos. We implement industry-leading practices to protect your data and maintain the trust you place in us.

Certifications & Compliance

  • SOC 2 Type II — Annual third-party audits
  • GDPR compliant — European data protection standards
  • CCPA compliant — California privacy regulations
  • ISO 27001 — In progress

Infrastructure Security

Data Centers

Our infrastructure is hosted on industry-leading cloud providers with:

  • 24/7 physical security
  • Biometric access controls
  • Redundant power and cooling
  • Geographic distribution for disaster recovery

Network Security

  • DDoS protection and mitigation
  • Web application firewall (WAF)
  • Intrusion detection and prevention
  • Regular vulnerability scanning

Data Protection

Encryption

  • In transit — All data encrypted using TLS 1.3
  • At rest — AES-256 encryption for stored data
  • Key management — Hardware security modules (HSMs)

Backups

  • Continuous backups with point-in-time recovery
  • Geographic redundancy across multiple regions
  • Regular backup testing and verification
  • 30-day backup retention by default

Application Security

Development Practices

  • Secure development lifecycle (SDLC)
  • Code reviews for all changes
  • Automated security scanning in CI/CD
  • Regular dependency updates
  • Static and dynamic application security testing (SAST/DAST)

Third-Party Audits

  • Annual penetration testing by independent security firms
  • Continuous vulnerability assessments
  • Bug bounty program for responsible disclosure

Access Controls

Authentication

  • Multi-factor authentication (MFA) available for all accounts
  • Single sign-on (SSO) for enterprise customers
  • Password requirements following NIST guidelines
  • Session management with automatic timeouts

Authorization

  • Role-based access control (RBAC)
  • Principle of least privilege
  • Regular access reviews
  • Comprehensive audit logs

Incident Response

Detection

  • 24/7 security monitoring
  • Automated alerting for anomalies
  • Threat intelligence integration
  • User behavior analytics

Response

  • Documented incident response plan
  • Dedicated security team
  • Regular incident response drills
  • Customer notification within 72 hours of any breach

Employee Security

  • Background checks for all employees
  • Mandatory security training
  • Annual security awareness updates
  • Strict policies for handling customer data
  • Access removed immediately upon termination

Vendor Management

We carefully vet all third-party vendors:

  • Security questionnaires and assessments
  • Data processing agreements (DPAs)
  • Regular vendor security reviews
  • SOC 2 reports required for critical vendors

Privacy by Design

We build privacy into every product decision:

  • Minimal data collection
  • Purpose limitation
  • Data minimization
  • Storage limitations
  • Transparent practices

For more details, see our Privacy Policy.

Customer Security Features

We provide security tools to help you protect your account:

  • Two-factor authentication (2FA)
  • IP allowlisting (Enterprise)
  • SSO integration (Enterprise)
  • Audit logs (Enterprise)
  • Role-based permissions
  • API key management with scopes

Reporting Security Issues

We take security reports seriously. If you discover a vulnerability:

  • Email — contact@lumos.com
  • PGP Key — Available upon request
  • Bug bounty — Eligible reports may receive rewards

Please do not publicly disclose vulnerabilities before we have had a chance to address them. We commit to:

  • Acknowledging your report within 24 hours
  • Providing regular updates on our progress
  • Crediting researchers (with permission)

Status Page

Monitor our service availability and incident history at status.Lumos.com.

Contact

For security-related questions:

  • Security team — contact@lumos.com
  • General inquiries — contact@lumos.com