Security & Trust

Your brand's voice, handled with care.

Lumo learns your brand, connects to your channels, and drafts your marketing, then waits for your yes. That's real trust to hold. Here's exactly how we protect your accounts, your content, and your data.

Last updated 21 July 2026
Encrypted end to end
TLS 1.2+ in transit, AES-256 at rest, across every draft, token, and asset.
Approval-gated
Nothing reaches your audience until a person signs off on it.
Least access
We request the narrowest channel permissions each platform allows.
Core controls

The safeguards under every workspace

Foundational protections that apply to every account on Lumo, from your first connected channel onward.

Encryption everywhere

All traffic runs over TLS 1.2 or higher. Stored data, including drafts, media, and channel tokens, is encrypted at rest with AES-256.

Isolated channel tokens

OAuth tokens for your connected accounts live in an encrypted vault, scoped per workspace, and are never exposed to the browser or logs.

Google sign-in only

Authentication runs entirely through Google, so there are no passwords for us to store or leak. Your login inherits your Google account's own 2FA.

Full audit trail

Every draft, edit, approval, and publish is logged with a timestamp and an actor, so you always know what went out and who approved it.

AI, kept in bounds

The AI drafts. A person always decides.

No autonomous posting

Everything Lumo generates enters your queue as a draft. It cannot reach a live channel until an approver greenlights it.

Your content isn't training data

The brand playbook, prompts, and drafts inside your workspace are never used to train foundation models.

Scoped brand access

The model only sees the workspace it's generating for. It can't reach another brand's playbook, media, or channels.

How we operate

Practices behind the product

Infrastructure
Hosted on SOC 2-compliant cloud providers with EU data residency. Production access is restricted, logged, and gated behind multi-factor authentication.
Least privilege
We request the minimum OAuth scopes each platform needs to schedule and publish. If a permission isn't required to do the job, we don't ask for it.
Data lifecycle
Disconnect any channel or delete your workspace at any time. On deletion, associated tokens and content are purged from active systems within 30 days.
Dependencies
Automated scanning watches our dependencies for known vulnerabilities, and patches are applied on a prioritized schedule.
Backups
Encrypted backups run on a regular cadence and are restore-tested, so an incident never means losing your work.
Data & access

What we hold, and who can touch it

What Lumo stores

  • Your drafts, scheduled posts, and published history
  • Media you upload to your library
  • Encrypted channel tokens used for scheduling
  • Your brand playbook and approval settings

Who has access

  • You and the teammates you invite to the workspace
  • Approvers you assign, scoped to their role
  • A limited set of Lumo staff, only for support you request
  • No advertisers, and we never sell or share your data
Status transparency

You can always see where a post stands

Every piece of content carries a clear status through its whole life, so nothing publishes by surprise.

Draft In review Scheduled Published

A post advances only as a person approves each step. Published is the one state visible to your audience, and it's never reached without your yes.

Responsible disclosure

Found something? Tell us.

We take security reports seriously and respond quickly. If you believe you've found a vulnerability, reach out and we'll work with you on it.

We aim to acknowledge every report within one business day.