Security & trust

Your documents are yours.

What we do today to protect the documents and data you send us.

Encrypted in transit

The website, app, API and webhooks are served only over HTTPS.

Your data stays in your account

Every request is scoped to your company, and team roles decide who can upload, approve, export and manage settings.

Credentials kept locked

Accounting connection tokens and webhook signing secrets are encrypted in our database. API keys are stored only as hashes and shown to you once.

Never used to train models

Documents are processed with Anthropic's Claude through its commercial API, which doesn't use API data to train models by default. We don't train models on your documents either.

People approve what leaves

Nothing is emailed to a supplier or vendor until someone on your team approves it, and accounting sync only happens after a document is approved.

An audit trail

Exports, approvals, API key changes, integration changes and any access change made by our staff are recorded in your account's audit log.

Signed webhooks

Every webhook is signed with your endpoint's secret, and we only deliver to public HTTPS addresses.

Payments through Stripe

Card details go directly to Stripe; they never touch our servers.

Deletion

Delete documents or your account.

Email hello@lumenglobalsourcing.com from your account's admin address to ask us to delete documents or your whole account, and we'll confirm when it's done.

Compliance

Where we are.

We don't have a SOC 2 report yet. When an audit is underway we'll say so here. Our Data Processing Addendum and Privacy Policy describe how we handle personal data.

Found a security issue?

Tell us.

Email hello@lumenglobalsourcing.com with the details. Please give us a chance to fix it before sharing it publicly.