Security at Lumiaxiom
Every artifact your security, procurement, and legal teams need to evaluate Lumiaxiom — policies, retention terms, sub-processors, and pre-filled questionnaire responses. For our live posture (framework status, controls in place, current sub-processors), see the Trust Center.
Security policies
Public summaries of our access control, encryption, incident response, and secure-SDLC policies.
Data retention & deletion
How long we keep each data class, tenant-controlled purge, and export on offboarding.
Evidence artifacts
SIG-lite responses, sub-processor list, pen-test summary, SBOM, and hash-chained audit exports.
Evaluation kit
A structured pack for security, procurement, and legal — everything a buyer needs to green-light Lumiaxiom.
Report a vulnerability, request a DPA, or ask for our latest evidence pack: security@lumiaxiom.com. We acknowledge within 24 hours.