Trust
Security & Data Protection
You're trusting us with health and financial information. Here is — in plain language — how that data is protected, what control you keep over it, and how to reach us if you find a problem.
Encrypted in transit and at rest
All traffic runs over TLS. Health and assessment data is encrypted at rest with authenticated symmetric encryption (AES with integrity checking), with support for routine key rotation. Decryption keys are never stored alongside the data.
Your data, your call
You can delete your account — and the assessments under it — at any time. Consumer reports never require an account, and disclosure of health detail to an advisor only happens when you explicitly turn it on.
Role-based access, enforced server-side
Advisors see only their own clients (and their firm's, when they're part of one). Every request is authorized against that boundary on the server — not in the browser.
Hardened sign-in
Sessions use HttpOnly cookies with CSRF protection. Changing or resetting your password signs out every other device and emails you a notice. Repeated failed sign-ins are slowed automatically and trigger an alert to you — never a lockout that someone could use against you. Two-factor authentication is available in Settings.
Drafts stay on your device
While you fill out an assessment, your draft is saved only in your own browser — it expires automatically and is cleared when you submit or sign out.
Audited, versioned, tested
Security-relevant actions are audit-logged. Every report records the engine version that produced it. The platform ships through automated tests, dependency vulnerability scanning, and secret scanning on every change.
What we are — and aren't
Lumis Life is an analytics platform, not a healthcare provider. Clients self-report through a secure intake form. You see actuarial results, not diagnoses or medical records. No HIPAA authorization needed because no protected health information is stored — and we don't claim HIPAA compliance. The Privacy Policy and Terms of Service spell out exactly what we collect and how it's used. We never sell your data.
Data retention & deletion
Delete your account and your assessments go with it. After an account is closed, residual assessment data is purged on a 90-day retention schedule. Consent-gated programs (like outcome tracking) treat consent withdrawal as a purge, not a flag.
Found a vulnerability?
We welcome good-faith security research. Email security@lumislife.comwith reproduction steps and we'll acknowledge within 3 business days. We won't pursue legal action against research that respects user data and gives us a reasonable window to fix issues before disclosure. Machine-readable details live at /.well-known/security.txt.
Questions about any of this? Write to security@lumislife.com — a human reads it.