Security

How Luumen protects your most sensitive data.

SOC 2 Type II
ISO 27001
End-to-End Encryption
CSTAR Accredited

Encryption and data handling

Customer data is protected at rest, in transit, and through its full lifecycle.

Encryption at rest

Datastores housing sensitive customer data are encrypted at rest using cloud-provider managed encryption.

Encryption in transit

Confidential and sensitive data is encrypted in transit using secure protocols whenever transmitted over public networks.

Key access controls

Privileged access to encryption keys is restricted to authorized personnel with a documented business need.

Classification & retention

A formal data classification policy governs handling of confidential data. Retention and disposal procedures ensure customer data is purged when a customer leaves the service.

Who can access what, and when

Fine-grained authentication, authorization, and audit controls across the platform.

Authentication

Unique credentials are required for all production system and application access. Password policies are enforced consistent with our internal standards.

SSO & directory sync

Enterprise SSO (SAML, OIDC, and Active Directory) and SCIM provisioning are available for centralized identity management.

Authorization

Production application access is restricted to authorized users only. Workspace-level roles and permissions scope what each user can see and do.

Audit logging

Audit logs capture privileged system and administrative actions in support of security review and incident investigation.

Monitoring & response

Continuous detection, scanning, and a documented response process for security events.

Network controls

Production network access requires unique authentication over an approved encrypted connection. Firewall rulesets are reviewed at least annually.

Intrusion detection

An intrusion detection system provides continuous monitoring of our production network to surface potential security events.

Vulnerability management

Formal vulnerability and system monitoring procedures govern continuous scanning of dependencies and infrastructure for known vulnerabilities.

Incident response

Security and privacy incidents are logged, tracked, resolved, and communicated to affected parties per our documented incident response policy.

Third parties we use

Apiphani uses the subprocessors below to deliver Luumen. For the canonical list and any recent changes, see our trust portal. Additional third-party platforms used for the Luumen marketing site are listed in our privacy policy.

Hosting & infrastructure
Amazon Web Services
Application hosting, infrastructure, storage, and LLM inference (Bedrock). AWS GovCloud is used for FedRAMP-bound environments where applicable.
AI & product analytics
LangSmith
LLM trace and prompt monitoring for LuumenAI features
PostHog
Product analytics on the Luumen application
Identity & authentication
Microsoft Azure
Identity / IAM in support of MS365 and Sign in with Outlook
Google Cloud Platform
Sign in with Google (OAuth)
WorkOS
Authentication and identity layer — OAuth, enterprise SSO (SAML/OIDC), and directory sync (SCIM)
Observability
Dynatrace
Application performance monitoring and infrastructure observability
Better Stack
Application log aggregation
Customer engagement
Stripe
Self-service billing and payment processing
Intercom
Customer support conversations
Frill
Customer feedback and feature request submissions

Trust portal

For our complete list of compliance controls, audit reports (SOC 2, ISO, CSTAR), policies, and the latest subprocessor changes, visit trust.apiphani.com. Customers and prospective customers can request access to confidential reports through the portal.

Responsible disclosure

Discover a vulnerability? Report it to [email protected]. We acknowledge reports promptly and triage according to our incident response policy. We do not pursue legal action against good-faith researchers acting within the scope of this program.