Trust & security

You are uploading your contracts. Here is exactly what happens to them.

Where the files live, who inside your company can open them, what the AI does with the text, and how you get everything back out. Written in plain language, including the parts we have not built yet.

Where it lives
The EU
The application runs in AWS Frankfurt; the database and contract files are in EU infrastructure. Files never sit outside it.
AI training
Never on your text
Not by Anthropic through its commercial API, and not by us.
Isolation
Row-level, in the database
Postgres enforces tenancy — not a filter in application code.
Getting out
Export any time · 30 days
Self-serve export; account data removed within 30 days of cancellation.

The journey of one contract

Every file you upload follows the same four steps. Only one of them leaves our infrastructure, and it is marked.

  1. EUStep 1

    Upload or forward

    The file lands in Supabase storage in the EU over TLS, scoped to your workspace.

  2. US · leaves our infraStep 2

    Text sent to Claude

    The contract text is sent to Anthropic's commercial API for extraction — the one point where content leaves Lumipact. Not used for training. Use your own key and it runs under your account instead.

  3. EUStep 3

    Fields returned and stored

    Extracted fields come back to your workspace, encrypted at rest, isolated by row-level security.

  4. EUStep 4

    Only named people open it

    Role and department scoping decide who sees it; every access and change is written to the audit log.

Email alerts go out through Resend (EU). Billing runs through Stripe and never touches contract data. Product analytics is EU-hosted and carries no contract content. Full list below.

The honest split

What we have, what you can ask for, and what we do not have yet.

Lumipact is an early-stage product run by a small team. Rather than describe our posture in the language of a mature vendor, here is the split — including the list that will fail some procurement processes today. We would rather you learn that here than three weeks into an evaluation.

Implemented today

  • EU hosting for application and database infrastructure
  • TLS in transit; encryption at rest by our infrastructure providers
  • Tenant isolation enforced by Postgres row-level security, not application-layer filtering
  • Role-based access control, with confidential contracts restrictable to named groups
  • An audit log of access and changes
  • Self-serve data export and account deletion

Available on request

  • Signed Data Processing Addendum
  • Subprocessor register with regions and processing purposes
  • A written description of our architecture and data flows for your security review
Request the security pack

Not in place

  • SOC 2, ISO 27001 or any other third-party certification
  • An independent penetration test
  • SAML/SSO or SCIM provisioning
  • A contractual uptime SLA or a formal incident-response SLA
  • A published, independently verified backup and restore guarantee

If your procurement process requires any of these, Lumipact will not pass it today.

The details, one topic at a time

Written for the person filling in your vendor questionnaire.

Hosting and infrastructure

Lumipact is hosted in the EU. The application runs in AWS Frankfurt and contract and auth data is stored in Supabase EU infrastructure. We use managed infrastructure with regular patching and baseline monitoring.

Encryption and secrets

Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Credentials and server-side keys are stored outside source control and are rotated when needed.

Access control

Access is tenant-scoped by default, and enforced by Postgres row-level security rather than by application code remembering to filter. Role-based permissions control who can see, edit and administer contracts. Sensitive agreements can be restricted to narrow groups, and actions are captured in an audit log.

GDPR and data handling

Lumipact is built for EU customers and GDPR expectations. Processing stays in supported regions, customer data is segregated by tenant, and export and deletion are supported. The DPA covers the detail.

Read the DPA

Portability and deletion

You can export contracts and structured metadata at any time, without asking us. If you cancel, we provide an export path and remove account data within 30 days unless you ask for a shorter window.

Incident response

We monitor availability and investigate suspicious behaviour as a priority. Security incidents affecting customer data are triaged immediately, contained, and communicated to affected customers with mitigation steps. There is no contractual response SLA today, and we will not imply one.

Everyone who touches your data

The full register, with regions and processing purposes, is in the DPA.

ProviderPurposeRegion
SupabaseDatabase, authentication and file storageEU
Amazon Web ServicesApplication hostingEU · Frankfurt
AnthropicAI contract extraction — contract text is processed. No training on your data.US · SCCs
ResendTransactional and inbound emailEU · west-1
StripeBilling. Never receives contract data.US · SCCs
PostHogProduct analytics. Carries no contract content.EU

Still have a question your questionnaire needs answered?

Write to a human. We answer security questions directly, and we will tell you plainly when the answer is no.

legal@lumipact.com

    We use privacy-friendly analytics to understand which pages are useful. No ads, no cross-site tracking. Read our cookie policy.