For InfoSec and IT

How the platform is built and run.

The controls behind the data-protection page — hosting, access, backup, recovery — stated as they are today, with what is not yet in place listed alongside.

How your data is protected

Encrypted in transit

All traffic to lumi is served over HTTPS/TLS. Your data is encrypted between your browser and our servers.

Hosted in the United Kingdom

lumi runs on Amazon Web Services in the United Kingdom (London). Data residency and hosting are set out in our Data Processing Agreement (DPA).

One organisation never sees another

Every organisation’s data is logically separated. Members only ever see anonymised aggregates — never another organisation’s raw answers.

Hardened accounts

Passwords are stored with bcrypt (never in plain text). Sessions are HttpOnly and SameSite; sign-in and password-reset are rate-limited against brute force, with tokenised, expiring reset and invite links.

Every action logged

Key actions are logged, so access and changes are traceable — the basis for accountability in any data-protection review.

Anonymity floor (n≥3)

When fewer than three employers answered a question, the whole card is hidden: on screen and in an export. No individual organisation’s data can be reverse-engineered from the benchmark.

Data protection

Handled under UK GDPR

Your data, your rights

  • Used for one thing — the shared benchmark. Never sold, never passed to third parties for their own purposes.
  • Data minimisation — lumi collects reward practice and policy answers, not individual employee records.
  • Export any time, and request deletion — we delete your data within 30 days of a verified request.
  • A Data Processing Agreement is available on request for members who need one.

Less to review, by design

  • No HRIS integration and no data pulled from your systems — lumi is a guided questionnaire, so there’s far less for IT and InfoSec to review.
  • No individual employee data ever enters lumi — nothing personal to breach.
  • Full sub-processor list published and kept current (below).
  • Happy to complete your security questionnaire or DPIA — just ask.
Sub-processors

Who touches your data

A short, current list — nothing more than we need to run the service.

ProviderPurposeRegion
Amazon Web ServicesCloud hosting & storageUnited Kingdom (London)
Postmark (Wildbit LLC / ActiveCampaign)Transactional email (invites, resets, alerts)United States — UK GDPR transfer safeguards (SCCs / UK Addendum)
AnthropicAI Insights: analytical summaries & Ask lumi answers, from aggregate figures (only when AI features are enabled)US · under SCCs / UK Addendum

The definitive list lives in our sub-processors page.

Certifications

We don’t yet hold SOC 2 or ISO 27001, and we won’t claim a certification we don’t have. Where we are, and where we are going. If you need something below sooner for a procurement process, tell us on the call — it helps us prioritise.

Certified Cyber Essentials — certified 7 September 2026 by Periculo, under IASME (certificate 000b5bc2-a54c-4f22-94ca-2d6188f58ddb, profile 3.3, scope: whole organisation). Recertification due 7 September 2027. The included cyber cover (AIG UK, £25,000 in the aggregate) runs to the same date.
On the roadmapSingle sign-on (SSO / SAML) — for annual members with an identity provider.
On the roadmapSOC 2 / ISO 27001 — as we scale, the recognised enterprise standards.
Available nowSecurity questionnaire & DPIA support — we’ll complete yours on request.
For your legal and data-protection teams

The paperwork, and the detail behind it.

Every document a due-diligence review asks for — the Data Sharing Agreement, privacy notice, sub-processor list and a completed security questionnaire — with an account of exactly what we collect and why a DPIA is unlikely to be needed.

Data protection pack

Bring your questionnaire.

Bring them to the demo, or email our data-protection contact directly.