Security

How we handle your data.

Lumis sits alongside your PM tool, not above it. We handle credentials the way we’d want ours handled. This page is the current accounting of controls, policies, and subprocessors. Security contact: security@lumis.work.

Controls in production

What’s live today on lumis.work and api.lumis.work.

Policies

What we commit to when the bad day happens, plus where we are on the compliance path.

Subprocessors

The infrastructure vendors that see a subset of your data in flight or at rest. A full DPA + subprocessor list with contractual terms ships at GA.

VendorPurposeRegionData
RailwayApplication hosting + Postgres + RedisUnited StatesAll operational data at rest
CloudflareDNS + TLS edge for lumis.work and api.lumis.workGlobalRequest metadata in flight
ResendTransactional email — invites, digests, alertsUnited StatesRecipient email + rendered email content
AnthropicAI clarity review, title suggestion, description suggestion (Claude)United StatesTask title + description + prompt metadata (per-call)
OpenAIText embeddings for cross-tool correlationUnited StatesTask title + description (per-call)
GitHubSource hosting. Not a data path for customer data.United StatesCodebase only — no customer data

If we add a subprocessor, we update this table before they see any customer data, and list the change in the changelog.

Procurement questions welcome.

Due-diligence questionnaires, SOC 2 pre-audit reports, custom DPAs — email security@lumis.work. We respond within one business day.

Join the waitlist