Security

Client files, handled like client files.

You are putting privileged material into someone else’s software. Here is what happens to it, in plain terms — including the parts that are still in progress.

Tenant isolation
Every matter, document and generated draft is scoped to your firm. Requests are authorised against the firm on your session, never against an identifier supplied by the browser.
Encryption
TLS in transit. Encryption at rest for documents and database content, managed by our infrastructure providers.
Your data is not training data
Nothing you upload is used to train models, ours or anyone else’s. Model providers process your content to answer the request and do not retain it for training.
Real deletion
Deleting a document removes what was derived from it as well — extracted facts, search embeddings and page text. Deleting a matter removes the matter and its documents.
Access control
Roles plus per-person permissions: who can create matters, delete documents, run agents, export, manage the client portal. Permission changes take effect immediately, without waiting for a re-login.
Session control
Passwords are hashed with bcrypt and must meet a strength policy. Changing a password or deactivating a user signs out every existing session for that account.
Audit trail
Sign-ins, document uploads and deletions, agent runs, permission changes and billing events are logged with the account that performed them.
Client portal
Clients upload through a single-purpose link, scoped to one matter and one request. No account to create, and no access to anything else in the firm.

Certifications, honestly

We are working toward SOC 2 Type II and will say so here the moment a report exists, with the audit period and the auditor named. Until then we will not display a badge we have not earned. If your firm needs a security questionnaire completed, a penetration-test summary or a data processing agreement, ask and we will send what we actually have.

Data processing agreement

Available on request for any paid plan. It covers processing purposes, sub-processors, retention, deletion and breach notification.

Request the DPA

Responsible disclosure

If you believe you have found a vulnerability, email security@luma.legal. We will confirm receipt within two business days and keep you updated until it is resolved. We will not pursue legal action against researchers acting in good faith who give us reasonable time to fix an issue before disclosing it.