Security

Security and Compliance

Lumiqo protects customer data with enterprise-grade cloud infrastructure, encryption, controlled access, and regional hosting support.

✓Microsoft Azure Infrastructure
✓Encryption in transit and at rest
✓Role-based access control
✓Regional hosting / data residency

How we protect data

Lumiqo protects data at every step of the workflow. Data is encrypted, access is restricted, and sensitive environments are separated.

What this means for you:

Your data is encrypted in transit and at rest using industry-standard protocols.
Access is limited to authorized people and systems.
Architecture runs on Microsoft Azure, which supplies the underlying encryption, network isolation and compliance certifications.
Security is built into the workflow, not added later.

Access control

We keep access tight by design. Only the people and systems that need access get access, limited by role and approval.

Controls include:

Role-based access control.
Multi-factor authentication is required for administrative and infrastructure access.
Access is removed when it is no longer needed.
Restricted production and encryption key access.

Hosting and residency

Lumiqo runs on Microsoft Azure, and data residency is configured per customer so data can be held in the region you require.

We make it clear:

Where data is hosted.
How regional separation works.
How we handle cross-border data concerns.

Compliance posture

We aim to meet the security expectations of B2B teams and enterprise procurement reviews, using the controls and certifications our cloud platform provides.

Current controls and commitments:

Built on SOC 2 compliant Azure infrastructure.
Data Processing Agreement (DPA) in place before processing begins.
Data handling designed to meet GDPR obligations.
Documented subprocessors.
Documented retention periods, with deletion on account closure or on request.

Logging and monitoring

We keep logs and traces to help with troubleshooting, incident review, and operational accountability.

This includes:

System and pipeline logs via Azure Monitor.
Quality and error tracking.
Authentication and access events are logged and reviewable after the fact.
Every pipeline run is recorded with its timestamp and outcome, so a delivered figure traces back to the run that produced it.

Data retention and deletion

We keep retention rules clear so customers know what happens to their data over time.

Our approach:

Retain only what is needed for the service.
Define how long raw and derived data is kept.
Delete data when accounts are closed or on request.
Document the process in plain language.

Privacy and governance

We also treat data governance as a product requirement, not an afterthought.

That means:

Sensitive data is handled with clear rules.
Access is limited.
The system is designed to support privacy obligations.
Security Packet

Need more than this page?

Our Data Processing Agreement and subprocessor list are published. Anything else, including a completed security questionnaire, on request.

Request the security packet
FAQ

Common security questions

SSO/SAML is on the enterprise roadmap. Today your data is operated by our team on your behalf, protected by role-based controls and MFA. Tell us your security requirements and we will walk you through the current setup.

Yes. We encrypt data in transit and at rest.

We support regional hosting on Microsoft Azure and can align with data residency needs.

Yes. Our DPA forms Annex 1 to our Terms of Service and applies from the point personal data is first processed.

Access is role-based, restricted, and reviewed.

Yes. Our DPA is Annex 1 to the Terms of Service and the subprocessor list is published in the Privacy Policy, so both can be linked straight into a review. Anything further, including completed questionnaires, on request.

Trusted data starts with clear controls.

If your team needs a B2B data platform that treats security and compliance as core product features, Lumiqo is ready for review.

Request the security packet