Trust Center
The security posture of a security company should be public.
LumixSys publishes its compliance certifications, security posture, sub-processor list, and operational telemetry — continuously. This page is the index.
Live security posture
The same numbers our exec team reviews every Monday.
Uptime (rolling 30d)
99.997%
Open P1 incidents
0
Mean detection (ARIA)
180ms
Crypto-agility coverage
100% of tenants
Sub-processors
12 · public list
Last pen test
Q1 2026 · Trail of Bits
Compliance & certifications
What we are continuously attested against.
SOC 2 Type II
Security, Availability, Confidentiality
Since Q1 2025audit refreshed continuously
ISO 27001:2022
Information Security Management System
Since Q3 2025
ISO 27701:2019
Privacy Information Management
Since Q4 2025
PCI DSS 4.0
Level 1 Service Provider
Since Q1 2026
GDPR (EU & UK)
Controller + Processor obligations
Since 2024
HIPAA + HITRUST CSF v11
Covered entity & Business Associate
Since Q4 2025BAA available
DORA (EU)
Articles 5–24 mapped
Since Q1 2026
CMMC L3
Defense Industrial Base
Since In process
FedRAMP High
US Federal Civilian
Since In process
Sub-processors
Every third party that touches customer data.
We notify all customers 30 days before adding any sub-processor. Subscribe to changes at trust-updates@lumixsys.com.
Vendor
Purpose
Region
- Amazon Web ServicesPrimary cloud hostingUS-EAST, US-WEST, EU-WEST, AP-SE
- Google Cloud PlatformSecondary cloud hostingUS-CENTRAL, EU-WEST
- CloudflareEdge & DDoS protectionGlobal
- DatadogInternal observabilityUS-EAST
- StripeSubscription billingUS
- Twilio SegmentProduct analytics (opt-in)US
- LinearEngineering issue trackingUS
- NotionInternal documentationUS
- Okta + WorkdayIDP and HRISUS
- AtlassianCode review and CIUS
- SnowflakeInternal data warehouseUS
- HashiCorp CloudSecrets management (employee)US
Documents
What you can request — and how fast.
Quarterly Trust ReportRead the Q1 2026 Trust Report
We publish what didn't hit target — every quarter.
Most security vendors publish marketing. We publish what broke, what we learned, and which SLOs we missed. The 2026 Q1 report includes 3 SLO deviations, 2 incident retrospectives, and the resulting roadmap.
3
SLO deviations Q1 2026
2
Customer-impacting incidents
0
Sensitive data exposed
Secure your infrastructure
Move to quantum-safe in a quarter — not a decade.
Talk with a Lumix architect about a 90-day post-quantum rollout, a live SpectraShield demo on your stack, and the breach math that should be on your board agenda this week.