Your documents are yours.
What we do today to protect the documents and data you send us.
Encrypted in transit
The website, app, API and webhooks are served only over HTTPS.
Your data stays in your account
Every request is scoped to your company, and team roles decide who can upload, approve, export and manage settings.
Credentials kept locked
Accounting connection tokens and webhook signing secrets are encrypted in our database. API keys are stored only as hashes and shown to you once.
Never used to train models
Documents are processed with Anthropic's Claude through its commercial API, which doesn't use API data to train models by default. We don't train models on your documents either.
People approve what leaves
Nothing is emailed to a supplier or vendor until someone on your team approves it, and accounting sync only happens after a document is approved.
An audit trail
Exports, approvals, API key changes, integration changes and any access change made by our staff are recorded in your account's audit log.
Signed webhooks
Every webhook is signed with your endpoint's secret, and we only deliver to public HTTPS addresses.
Payments through Stripe
Card details go directly to Stripe; they never touch our servers.
Delete documents or your account.
Email hello@lumenglobalsourcing.com from your account's admin address to ask us to delete documents or your whole account, and we'll confirm when it's done.
Where we are.
We don't have a SOC 2 report yet. When an audit is underway we'll say so here. Our Data Processing Addendum and Privacy Policy describe how we handle personal data.
Tell us.
Email hello@lumenglobalsourcing.com with the details. Please give us a chance to fix it before sharing it publicly.