Compliance
Independent assurance and certifications for the Lumios Web Application. Supporting documents are available upon approved request.
SOC 2 Type 2
SOC 2 Type II examination of the Lumios System for the period March 1 through May 31, 2026.
ISO 27001
ISO/IEC 27001:2022 certification for the management system supporting the Lumios Web Application. Certificate valid through July 16, 2029.
ISO 27701
ISO/IEC 27701:2019 certification for the privacy management system supporting the Lumios Web Application. Certificate valid through July 16, 2029.
Resources
Read our public policies and request access to our assurance reports and certificates.
Privacy Policy
How Lumios collects, uses, and protects personal information.
Terms of Service
Terms governing use of the Lumios platform and handling of customer data.
SOC 2 Type II Report
Independent service auditor report covering March 1 through May 31, 2026. Available upon approved request.
ISO/IEC 27001:2022 Certificate
Insight Assurance certificate for the management system supporting the Lumios Web Application. Issued July 17, 2026; expires July 16, 2029.
ISO/IEC 27701:2019 Certificate
Insight Assurance certificate for the privacy management system supporting the Lumios Web Application. Issued July 17, 2026; expires July 16, 2029.
Subprocessors
Service providers that support the Lumios platform and may process customer data in providing their services.
Neo4J
Graph database to handle data relationships
OpenAI
Lumios uses OpenAI's API across the document pipeline. GPT-4o, 4o-mini, and GPT-5 family models drive fact extraction, document processing, vision OCR, discovery tagging, entity deduplication, interaction extraction, feature extraction, OOP drafting, chat, and aggregate insights. text-embedding-3-small generates embeddings for semantic search and dedup; Whisper transcribes audio. Customer documents and case data are sent to OpenAI via the SDK. Billed through our OpenAI Platform account.
Vercel
Deploy frontend
AWS
Cloud infrastructure provider. Lumios's production environment and all customer-data storage run on AWS (us-east-1).
Anthropic
Lumios uses Anthropic's Claude API as the core LLM powering our product. Claude (Opus, Sonnet, Haiku 4.x) drives agentic chat, multi-doc briefings, deposition outlines, draft and objection generation, legal hold notices and reply classification, docket processing, and portfolio agent loops. Customer case data — documents, facts, communications — is sent to Claude via the Anthropic SDK. API access is keyed and billed through our Anthropic Console account.
Cloudflare
CDN and web application firewall protecting traffic to the Lumios platform.
Cohere
Reranker to compare queries and possible options
Google Workspace
Email, documents, calendar, and SSO identity provider.
Monitoring
FAQs
Answers to common questions about how Lumios handles customer information.