Back to Home

Trust Center

Last Updated: June 11, 2026

This is our plain-language statement of how Lumina handles your data and where we stand on compliance. We do not claim certifications we have not earned: an architecture is "designed to support" a framework until an audit is passed.

Security architecture

Lumina runs on a local-first architecture. A full analytical SQL engine runs on your own device, inside the browser, and your datasets are processed and persisted locally. Raw data is never uploaded to our servers.

To answer a question, the AI receives only the structure it needs: column names, data types, and a small sample (typically the first 5 to 20 rows). The full dataset stays on the device. This sample is the single point where field-level values leave the browser, and it is governed by the in-product Firewall and data-loss-prevention controls.

Detailed architecture and security documentation, including the data-flow diagram and our internal control set, is available to qualified buyers under NDA or on request.

Verifiable, glass-box reasoning

Trust is not only about where data sits; it is about whether you can check the answer. Lumina is built for glass-box, verifiable AI: the model reasons, but your rules, thresholds, and standards live outside it as owned, versioned, auditable IP. Every answer can be traced back to the rule and the query that produced it, so a result is something you can inspect rather than take on faith.

What we store, and where

  • On your device only: raw datasets, SQL queries, and analysis results.
  • In Google Firestore: account profile, plan, LUM wallet balance and history, chat feedback, and any agent memories you choose to sync.
  • In Google Firebase Auth: identity (email, name, encrypted credentials).
  • With Stripe: payment processing. Full card details are tokenized by Stripe and never stored by us.

Encryption and access control

  • In transit: all network traffic is encrypted with TLS.
  • At rest: data held in Firestore and in on-device browser storage is encrypted at rest by the underlying platform.
  • Access: authentication is handled by Firebase Auth, with server-side identity verification and Firestore security rules enforcing per-user access.

Sub-processors

ProviderPurposeRegion
Google Cloud (Gemini API)LLM processing of query metadata and a small data sampleUnited States
Google Firebase (Auth + Firestore)Authentication, account profile, plan, LUM wallet, opt-in memoriesUnited States · Canada (optional)
Google Cloud Run + Cloud BuildApplication hosting and deployment pipelineUnited States · Canada (optional)
StripePayment processing (card data tokenized by Stripe, never stored by us)United States
SendGridTransactional and campaign emailUnited States

Compliance status

We do not claim certifications we have not earned.

FrameworkStatusDetail
SOC 2 (Type II)In progressNot yet certified. Architecture designed to support the Trust Services Criteria. Formal readiness assessment and control validation are underway.
ISO 27001EvaluatingNot yet certified. Under evaluation for international and EU customers.
GDPRAligned by designData minimization built into the local-first architecture. See our Privacy Policy.
PIPEDA / PIPA (Canada)AlignedPyxonData Inc. is an Alberta company. See our Privacy Policy.
HIPAAArchitecture supportLocal-first processing keeps raw data on the device. A signed BAA is required for any covered use and is not yet offered.

Data residency

PyxonData Inc. is based in Alberta, Canada. Cloud infrastructure and sub-processors are hosted in the United States. Because raw datasets stay on the device, the data that crosses a border is limited to account information and query metadata. See our Privacy Policy for international transfer details.

Intellectual property

Lumina's method for multi-agent conflict resolution, the technology behind the Boardroom, is the subject of a pending U.S. provisional patent application (No. 63/955,994). Patent pending.

Responsible disclosure

Report security vulnerabilities to support@lumina.express. We ask for a reasonable opportunity to investigate and remediate before public disclosure, and we do not pursue legal action against researchers acting in good faith.

Enterprise security review

Organizations evaluating Lumina for a regulated environment can contact support@lumina.express for security documentation, the data-flow diagram, and a discussion of specific compliance requirements. See our Enterprise deployment options or book a demo to walk through your requirements.