



Encryption and data handling
Customer data is protected at rest, in transit, and through its full lifecycle.
Encryption at rest
Datastores housing sensitive customer data are encrypted at rest using cloud-provider managed encryption.
Encryption in transit
Confidential and sensitive data is encrypted in transit using secure protocols whenever transmitted over public networks.
Key access controls
Privileged access to encryption keys is restricted to authorized personnel with a documented business need.
Classification & retention
A formal data classification policy governs handling of confidential data. Retention and disposal procedures ensure customer data is purged when a customer leaves the service.
Who can access what, and when
Fine-grained authentication, authorization, and audit controls across the platform.
Authentication
Unique credentials are required for all production system and application access. Password policies are enforced consistent with our internal standards.
SSO & directory sync
Enterprise SSO (SAML, OIDC, and Active Directory) and SCIM provisioning are available for centralized identity management.
Authorization
Production application access is restricted to authorized users only. Workspace-level roles and permissions scope what each user can see and do.
Audit logging
Audit logs capture privileged system and administrative actions in support of security review and incident investigation.
Monitoring & response
Continuous detection, scanning, and a documented response process for security events.
Network controls
Production network access requires unique authentication over an approved encrypted connection. Firewall rulesets are reviewed at least annually.
Intrusion detection
An intrusion detection system provides continuous monitoring of our production network to surface potential security events.
Vulnerability management
Formal vulnerability and system monitoring procedures govern continuous scanning of dependencies and infrastructure for known vulnerabilities.
Incident response
Security and privacy incidents are logged, tracked, resolved, and communicated to affected parties per our documented incident response policy.
Third parties we use
Apiphani uses the subprocessors below to deliver Luumen. For the canonical list and any recent changes, see our trust portal. Additional third-party platforms used for the Luumen marketing site are listed in our privacy policy.
Trust portal
For our complete list of compliance controls, audit reports (SOC 2, ISO, CSTAR), policies, and the latest subprocessor changes, visit trust.apiphani.com. Customers and prospective customers can request access to confidential reports through the portal.
Responsible disclosure
Discover a vulnerability? Report it to [email protected]. We acknowledge reports promptly and triage according to our incident response policy. We do not pursue legal action against good-faith researchers acting within the scope of this program.