Security and compliance, continuously verified
We hold ourselves to the same continuous operational control we sell — every claim below is wired to the same evidence ledger our customers use.
This page is maintained by Lumiaxiom and describes our own product controls, sub-processors, and current audit posture. It is not an independent certification, audit report, or third-party attestation. Framework statuses labelled "Compliant" reflect our own self-assessment against the referenced regulation; formal audits (SOC 2 Type II, ISO 27001) are in the timelines shown above. Customers evaluating Lumiaxiom for regulated use should request our latest audit letter, SIG/CAIQ questionnaire, or a reference call before onboarding.
Framework status
Sub-processors
| Vendor | Purpose | Region |
|---|---|---|
| Managed Postgres platform | Primary database, auth, object storage | EU (Frankfurt) |
| Cloudflare | Edge compute, DDoS protection, CDN | Global |
| Resend | Transactional email | US |
| Anthropic / Google | AI inference for finding analysis | US (zero-retention API) |
Controls in place
- Hash-chained evidence ledger (tamper-evident)
- Row-level security on every tenant table
- TLS 1.3 in transit; AES-256 at rest
- OAuth-based SSO with per-org role scoping
- Quarterly access reviews; least-privilege defaults
- All secrets stored in a managed secret vault
Email support@lumiaxiom.com. We acknowledge within 24h and remediate critical issues within 7 days.