Back to Lumiqs

Trust center

Security at Lumiqs

Security is part of the product contract: identity, access, business isolation, and honest communication about what we have and have not certified.

Last updated: August 19, 2026

Authentication and access

Lumiqs uses Clerk for authentication and server-side token verification. API requests derive the authenticated user from the verified session rather than trusting user IDs supplied by the browser.

Business data isolation

Business ownership and resource ownership are checked server-side. Conversations, reports, insights, memories, and AI context are scoped to the authenticated business.

Infrastructure

The application uses HTTPS-enabled hosting, MongoDB Atlas for database hosting, Supabase Storage where configured, and environment-managed secrets. AI provider calls happen on the server and API keys are not sent to the browser.

Monitoring and response

We monitor health and application errors, apply rate limits to expensive AI routes, and audit sensitive operations where implemented. Report a suspected vulnerability privately to support@lumiqs.ai.

Certifications

Lumiqs does not claim SOC 2, ISO 27001, HIPAA, GDPR certification, or other certifications unless explicitly announced and independently verified.

These pages are product templates, not legal advice. Have them reviewed by qualified counsel before commercial launch.