Lumo learns your brand, connects to your channels, and drafts your marketing, then waits for your yes. That's real trust to hold. Here's exactly how we protect your accounts, your content, and your data.
Foundational protections that apply to every account on Lumo, from your first connected channel onward.
All traffic runs over TLS 1.2 or higher. Stored data, including drafts, media, and channel tokens, is encrypted at rest with AES-256.
OAuth tokens for your connected accounts live in an encrypted vault, scoped per workspace, and are never exposed to the browser or logs.
Authentication runs entirely through Google, so there are no passwords for us to store or leak. Your login inherits your Google account's own 2FA.
Every draft, edit, approval, and publish is logged with a timestamp and an actor, so you always know what went out and who approved it.
Everything Lumo generates enters your queue as a draft. It cannot reach a live channel until an approver greenlights it.
The brand playbook, prompts, and drafts inside your workspace are never used to train foundation models.
The model only sees the workspace it's generating for. It can't reach another brand's playbook, media, or channels.
Every piece of content carries a clear status through its whole life, so nothing publishes by surprise.
A post advances only as a person approves each step. Published is the one state visible to your audience, and it's never reached without your yes.
We take security reports seriously and respond quickly. If you believe you've found a vulnerability, reach out and we'll work with you on it.
We aim to acknowledge every report within one business day.