Security and trust

Security you can examine.

Lumecon is formalizing its security program against the AICPA Trust Services Criteria, with a future SOC 2 Type II examination as the target. We have not completed a SOC 2 examination and do not currently have a SOC 2 report.

Start a security review

Control program

What is implemented and what remains in progress.

During private beta, the deployed configuration and customer requirements are reviewed before sensitive records move. Procurement documentation can cover hosting, subprocessors, access management, retention and deletion, incident response and backup and recovery.

Implemented in the product

Application controls

  • Authenticated access with server-side ownership checks for protected resources
  • Project permissions enforced for participant roles and changes in access
  • Deleted accounts locked out with active sessions invalidated
  • Opt-in observability configuration with required personal-data redaction

Program work underway

Readiness and evidence

  • Formal control inventory, ownership and evidence collection
  • Vendor, subprocessor and AI-provider review
  • Incident-response, backup and recovery testing and documentation
  • Examination scope, readiness review and independent auditor planning

This page describes current product design and program status; it is not a certification, audit opinion or contractual warranty. Confirm requirements and the deployed configuration during procurement.

Cedar and customer data

Provider terms are verified before sensitive content moves.

Some Cedar functions may use third-party AI providers. During private beta, Lumecon is finalizing written terms and technical controls covering each provider’s processing purpose, retention, access and model-training practices. Those arrangements are confirmed for the deployment and documented during security review before sensitive customer content is routed to a provider.

Lumecon does not sell personal information or use customer information for third-party advertising. Read the AI and Data Use statement and Privacy Policy for the current public terms.

Procurement

Bring your requirements to the review.

Government, Tribal, university and enterprise reviews differ. We will identify which controls, provider agreements and evidence are complete, in progress or not yet available for the deployment you are considering.

Contact the team