For Consulting Engagements
Platform security and consulting security are different problems. Consulting engagements follow their own discipline:
Access scoped per engagement
Named accounts, least privilege, and access agreed in the statement of work, requested when needed, surrendered when done.
Credentials handled like production secrets
Client credentials live in an encrypted vault, never in email, chat, or plain-text notes, and never shared between engagements.
Play before Live, always
Changes are proven in a rehearsal environment before production sees them. Production changes follow the change control agreed in your SOW.
Your data stays in your systems
We work inside your environments. Extracts for migration work are minimized, encrypted, and destroyed on a schedule you approve.
Built to Earn Your Trust
SOC 2 Type II
Security controls built to SOC 2 standards (independent audit underway), covering availability, confidentiality, and processing integrity.
AES-256 Encryption
All data encrypted at rest using AES-256. All data in transit encrypted via TLS 1.3. No exceptions.
Single-Tenant Isolation
Every customer gets their own model, their own environment, and their own encryption keys. Your data never mixes with anyone else's.
99.9% Uptime
Enterprise-grade infrastructure with redundant systems, automatic failover, and real-time monitoring.
GDPR & CCPA ready
Full data processing agreements, right to deletion, and data portability. Built to meet GDPR, CCPA, and industry-specific regulations.
How We Handle Your Data
Read-Only Access
The Lumina platform connects to your ERP database with read-only credentials, the platform never writes, modifies, or deletes records in your production system. Consulting engagements are separate: access is scoped per engagement, and any production change follows the change control agreed in your statement of work.
Data Minimization
We only ingest the data needed for your configured use cases. You control exactly which tables, fields, and date ranges we access.
Retention Control
You define how long we retain your data. Delete your Lumina ERP instance and all associated data is permanently purged within 72 hours.
Access Logging
Every data access, model query, and agent action is logged with timestamps, user identity, and full audit trail. Exportable anytime.
Compliance & Certifications
- SOC 2 Type II audit in progress
- GDPR & CCPA ready
- TLS 1.3 for all data in transit
- AES-256 encryption at rest
- Independent penetration testing (planned)
- Role-based access controls (RBAC)
- Multi-factor authentication (MFA)
- Incident response plan with 24-hour notification
Security Architecture Overview
Your ERP
Read-only connection
Your premises
Lumina Platform
Isolated tenant
AES-256 encrypted
Your Team
RBAC + MFA
Audit logged