Security at Lumetric
Your delivery data tells the story of your company. We protect it like it's ours.
Type II certified
Audited every year by an independent firm.
Certified since 2024
Covering every system and office.
Encrypted everywhere
AES-256 at rest, TLS 1.3 in transit, and per-workspace keys on the Scale plan.
Access controls
- SAML single sign-on
- SCIM user provisioning
- Role-based permissions
- Full audit log
No source code
We read metadata only. Code never leaves your Git host.
EU residency
Keep every byte in Frankfurt on Scale.
Security is part of how we build
Our security team reports directly to the CTO and reviews every change that touches customer data.
-
01
Least-privilege access
Engineers have no standing access to production data. Access is time-limited, approved and logged.
-
02
Continuous testing
Automated scanning on every commit, plus two external penetration tests a year.
-
03
Responsible disclosure
Our bug bounty programme has paid researchers for 60+ reports since 2023.
-
04
Business continuity
Hourly backups, multi-zone hosting and a tested recovery plan with a four-hour target.
Need our security pack?
Request our SOC 2 report, penetration test summary and completed security questionnaires.