Live posture

Security and compliance, continuously verified

We hold ourselves to the same continuous operational control we sell — every claim below is wired to the same evidence ledger our customers use.

Disclaimer

This page is maintained by Lumiaxiom and describes our own product controls, sub-processors, and current audit posture. It is not an independent certification, audit report, or third-party attestation. Framework statuses labelled "Compliant" reflect our own self-assessment against the referenced regulation; formal audits (SOC 2 Type II, ISO 27001) are in the timelines shown above. Customers evaluating Lumiaxiom for regulated use should request our latest audit letter, SIG/CAIQ questionnaire, or a reference call before onboarding.

Framework status

SOC 2 Type II
In progress
Q4 2026
ISO 27001:2022
Controls mapped
Audit Q1 2027
EU AI Act
Compliant
Self-attested
GDPR
Compliant
DPA available

Sub-processors

VendorPurposeRegion
Managed Postgres platformPrimary database, auth, object storageEU (Frankfurt)
CloudflareEdge compute, DDoS protection, CDNGlobal
ResendTransactional emailUS
Anthropic / GoogleAI inference for finding analysisUS (zero-retention API)

Controls in place

  • Hash-chained evidence ledger (tamper-evident)
  • Row-level security on every tenant table
  • TLS 1.3 in transit; AES-256 at rest
  • OAuth-based SSO with per-org role scoping
  • Quarterly access reviews; least-privilege defaults
  • All secrets stored in a managed secret vault
Report a vulnerability

Email support@lumiaxiom.com. We acknowledge within 24h and remediate critical issues within 7 days.