SOC 2 Type II Compliance

Lumin maintains a SOC 2 Type II report and follows industry-standard security practices to protect customer data. Our security program includes independent audits, annual penetration testing, secure software development practices, encryption, employee security awareness training, and a coordinated vulnerability disclosure program.

Table of contents

  • SOC 2 Type II Report
  • Security Awareness Training
  • Penetration Tests
  • Secure Software Development Lifecycle (SSDLC)
  • Data Protection & Encryption
  • Vulnerability Disclosure Program
  • Request SOC 2 Type II Report

SOC 2 Type II Report

We maintain an annually audited SOC 2 Type II report demonstrating both the design and operating effectiveness of our security controls.

SOC 2 Type II validates both the design and operational effectiveness of our security controls over the audit period.

Developed by the Assurance Services Executive Committee (ASEC) of the AICPA, the Trust Services Criteria is the set of control criteria to be used when evaluating the suitability of the design and operating effectiveness of controls relevant to the security, availability, or processing integrity of information and systems, or the confidentiality or privacy of the information processed by the systems at an entity, a division, or an operating unit of an entity.

Security Awareness Training

Security is a company-wide endeavor. All employees complete an annual security training program and employ best practices when handling customer data.

Penetration Tests

Independent security firms perform quarterly vulnerability scans and annual penetration tests. Findings are reviewed, prioritized, and remediated according to our vulnerability management process.

Secure Software Development Lifecycle (SSDLC)

Lumin utilizes a variety of manual and automatic data security and vulnerability checks throughout the software development lifecycle.

Data Protection & Encryption

Data is encrypted both in-transit using TLS and at rest.

Vulnerability Disclosure Program

Lumin operates a coordinated Vulnerability Disclosure Program. Security researchers can responsibly disclose vulnerabilities to our security team, where reports are reviewed, validated, and triaged in accordance with our vulnerability handling process. If you believe you’ve discovered a bug in Lumin’s security, please get in touch at [email protected].

Request SOC 2 Type II Report

Contact the Lumin support team to request a copy of our SOC 2 Type II report.

Last updated: August 2026