DNS TXT or well-known file verification precedes publication.
Lumeo Trust Center
Trust you can inspect.
This page separates controls implemented in the product from controls that depend on deployment configuration. It is not a certification statement.
Current assurance position
Lumeo does not currently claim SOC 2, ISO 27001, PCI DSS, or other independent certification on this site. Payment-card processing is delegated to configured payment providers; customers remain responsible for reviewing their own compliance obligations.
Control register
What the platform enforces today
Canonical facts retain source references and observed timestamps.
Redirects and resolved addresses are checked to reject private or non-global targets.
Consequential tools can stop before execution for an authorized owner decision.
Client secrets are shown once and stored as hashes with explicit scopes.
Gateway outputs include a SHA-256 Content-Digest.
Signing activates only after a deployment supplies and protects its signing key.
Production uploads require S3-compatible storage or an explicitly persistent directory.
The adapter requires a selected facilitator and independently reviewed settlement configuration.
Data handling
Source credentials are stored separately from source records and encrypted when the required deployment key is configured.
Responsible execution
Tool risk classes, required scopes, idempotency, bounded webhooks, and approval decisions are recorded around execution.
Incident contact
Report a suspected vulnerability privately. Include the affected route, reproduction conditions, and potential impact.
Need to complete a vendor review?
We can provide an architecture walkthrough and answer control-specific questions.