Our Commitment
Security is at the core of everything we do at Lumos. We implement industry-leading practices to protect your data and maintain the trust you place in us.
Certifications & Compliance
- SOC 2 Type II — Annual third-party audits
- GDPR compliant — European data protection standards
- CCPA compliant — California privacy regulations
- ISO 27001 — In progress
Infrastructure Security
Data Centers
Our infrastructure is hosted on industry-leading cloud providers with:
- 24/7 physical security
- Biometric access controls
- Redundant power and cooling
- Geographic distribution for disaster recovery
Network Security
- DDoS protection and mitigation
- Web application firewall (WAF)
- Intrusion detection and prevention
- Regular vulnerability scanning
Data Protection
Encryption
- In transit — All data encrypted using TLS 1.3
- At rest — AES-256 encryption for stored data
- Key management — Hardware security modules (HSMs)
Backups
- Continuous backups with point-in-time recovery
- Geographic redundancy across multiple regions
- Regular backup testing and verification
- 30-day backup retention by default
Application Security
Development Practices
- Secure development lifecycle (SDLC)
- Code reviews for all changes
- Automated security scanning in CI/CD
- Regular dependency updates
- Static and dynamic application security testing (SAST/DAST)
Third-Party Audits
- Annual penetration testing by independent security firms
- Continuous vulnerability assessments
- Bug bounty program for responsible disclosure
Access Controls
Authentication
- Multi-factor authentication (MFA) available for all accounts
- Single sign-on (SSO) for enterprise customers
- Password requirements following NIST guidelines
- Session management with automatic timeouts
Authorization
- Role-based access control (RBAC)
- Principle of least privilege
- Regular access reviews
- Comprehensive audit logs
Incident Response
Detection
- 24/7 security monitoring
- Automated alerting for anomalies
- Threat intelligence integration
- User behavior analytics
Response
- Documented incident response plan
- Dedicated security team
- Regular incident response drills
- Customer notification within 72 hours of any breach
Employee Security
- Background checks for all employees
- Mandatory security training
- Annual security awareness updates
- Strict policies for handling customer data
- Access removed immediately upon termination
Vendor Management
We carefully vet all third-party vendors:
- Security questionnaires and assessments
- Data processing agreements (DPAs)
- Regular vendor security reviews
- SOC 2 reports required for critical vendors
Privacy by Design
We build privacy into every product decision:
- Minimal data collection
- Purpose limitation
- Data minimization
- Storage limitations
- Transparent practices
For more details, see our Privacy Policy.
Customer Security Features
We provide security tools to help you protect your account:
- Two-factor authentication (2FA)
- IP allowlisting (Enterprise)
- SSO integration (Enterprise)
- Audit logs (Enterprise)
- Role-based permissions
- API key management with scopes
Reporting Security Issues
We take security reports seriously. If you discover a vulnerability:
- Email — contact@lumos.com
- PGP Key — Available upon request
- Bug bounty — Eligible reports may receive rewards
Please do not publicly disclose vulnerabilities before we have had a chance to address them. We commit to:
- Acknowledging your report within 24 hours
- Providing regular updates on our progress
- Crediting researchers (with permission)
Status Page
Monitor our service availability and incident history at status.Lumos.com.
Contact
For security-related questions:
- Security team — contact@lumos.com
- General inquiries — contact@lumos.com