Hosting and infrastructure
Lumipact is hosted in the EU. The application runs in AWS Frankfurt and contract and auth data is stored in Supabase EU infrastructure. We use managed infrastructure with regular patching and baseline monitoring.
Where the files live, who inside your company can open them, what the AI does with the text, and how you get everything back out. Written in plain language, including the parts we have not built yet.
Every file you upload follows the same four steps. Only one of them leaves our infrastructure, and it is marked.
The file lands in Supabase storage in the EU over TLS, scoped to your workspace.
The contract text is sent to Anthropic's commercial API for extraction — the one point where content leaves Lumipact. Not used for training. Use your own key and it runs under your account instead.
Extracted fields come back to your workspace, encrypted at rest, isolated by row-level security.
Role and department scoping decide who sees it; every access and change is written to the audit log.
Email alerts go out through Resend (EU). Billing runs through Stripe and never touches contract data. Product analytics is EU-hosted and carries no contract content. Full list below.
Lumipact is an early-stage product run by a small team. Rather than describe our posture in the language of a mature vendor, here is the split — including the list that will fail some procurement processes today. We would rather you learn that here than three weeks into an evaluation.
If your procurement process requires any of these, Lumipact will not pass it today.
Written for the person filling in your vendor questionnaire.
Lumipact is hosted in the EU. The application runs in AWS Frankfurt and contract and auth data is stored in Supabase EU infrastructure. We use managed infrastructure with regular patching and baseline monitoring.
Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Credentials and server-side keys are stored outside source control and are rotated when needed.
Access is tenant-scoped by default, and enforced by Postgres row-level security rather than by application code remembering to filter. Role-based permissions control who can see, edit and administer contracts. Sensitive agreements can be restricted to narrow groups, and actions are captured in an audit log.
Lumipact is built for EU customers and GDPR expectations. Processing stays in supported regions, customer data is segregated by tenant, and export and deletion are supported. The DPA covers the detail.
Read the DPAYou can export contracts and structured metadata at any time, without asking us. If you cancel, we provide an export path and remove account data within 30 days unless you ask for a shorter window.
We monitor availability and investigate suspicious behaviour as a priority. Security incidents affecting customer data are triaged immediately, contained, and communicated to affected customers with mitigation steps. There is no contractual response SLA today, and we will not imply one.
The full register, with regions and processing purposes, is in the DPA.
Write to a human. We answer security questions directly, and we will tell you plainly when the answer is no.
legal@lumipact.comWe use privacy-friendly analytics to understand which pages are useful. No ads, no cross-site tracking. Read our cookie policy.