Security

Your data stays yours. Encrypted, isolated, auditable.

The reports we work with decide what a mine, a road or a shipment does next. We treat the data behind them the way your client’s auditor would want us to: encrypted everywhere, kept in your environment, never shared, and traceable to the row it came from.

Encrypted everywhere

TLS 1.2 or newer in transit, AES-256 at rest. No exception for backups, logs or exports.

Runs where your data lives

The generator runs on infrastructure you control. Nothing has to leave your plant or your cloud to build a first artifact.

Never used to train

Your documents, criteria and Brain train nothing and are shared with no one. Not another customer, not a model vendor.

Every figure carries its source

Each value on a document points back to the file, page and row it came from. A question about a number is answered in seconds, with evidence.

How it is built

Three decisions that make the rest possible.

01

Your environment, not ours

Artifacts and the Brain run inside your plant or your cloud account. We connect to what you already have and write where your team already looks. There is no Lucum data lake, and no vendor security review stands between you and a first artifact.

02

One company, one Brain

The Brain that learns your criteria, limits and vocabulary is yours alone. It is isolated at the account, network and storage level from every other company we work with, and it goes with you if you leave.

03

Nothing in the path decides alone

The path that decides whether a certificate prints or a value is inside tolerance is a rule, reproducible and testable. A model helps find the rules; it is never the thing that makes the document correct. That is what an auditor needs to hear, and it is true.

Questions we get from security teams

Asked before the first artifact.

Do you train models on our data?

No. Your documents, criteria and Brain are used to build your artifacts and nothing else. They are not used to train or fine-tune any model, ours or a vendor’s, and they are never pooled with another company’s.

Where does our data live?

In your environment: your plant, your cloud account, your region. The generator runs there and writes there. We do not operate a central store of customer data.

Is our data encrypted?

Yes, in transit with TLS 1.2 or newer and at rest with AES-256, including backups, logs and exports. Keys stay under your control.

What happens to our data if we stop working with you?

Everything installed keeps running in your environment. Any working copy we hold is deleted and the deletion is confirmed in writing. The Brain is yours; it goes nowhere.

More detail

Encrypted in transit, at rest, and in every copy.
In transit
TLS 1.2 or newer on every connection, TLS 1.3 wherever the other end supports it. HSTS on every hostname we operate. No plaintext protocol is accepted, inside or outside your network.
At rest
AES-256 for databases, object storage, backups and exports. Keys live in your cloud provider’s key management service or in a hardware module you control; we never hold a key we could use without you.
Secrets
Credentials, tokens and keys are never written to a repository, a ticket or a chat. They live in a secrets manager, are rotated on a schedule, and are revoked the day a person or a system no longer needs them.
Retention
Your data stays in your systems. Working copies we need during an engagement are deleted when it ends, and we confirm the deletion in writing. Nothing you send us is kept as a sample, a benchmark or a demo.
Backups
Encrypted with the same standard as the primary copy, tested by restoring them, and kept in the region you choose. A backup is not a loophole for retention: it follows the same deletion.
Provenance
Every value an artifact writes carries its source, and every correction carries a name and a date. The audit trail is part of the document, not a log somebody has to go and find.
Named people, least privilege, nothing shared.

Least privilege, named access

Every person and every system has its own identity and only the permissions the work needs. Shared accounts do not exist. Access is granted with a name, a reason and an end date, and reviewed every quarter.

Multi-factor on everything

Hardware or app-based second factors on every account that can reach your data or our code, with no exception for founders or contractors.

Separate environments

Development, testing and production are separate accounts with separate credentials. Nothing is tested against production data unless you have agreed to it, in writing, for a named purpose.

Reviewed and checked before it ships

Every change is reviewed by a second person and passes automated checks before it can reach production. Dependencies are updated on a schedule; a critical vulnerability is patched within seventy-two hours of disclosure.

Logged and attributable

Access to your data and changes to an artifact are logged with who, what and when, and the logs are kept where you can read them. If your client asks who touched a number, the answer exists.

Incidents, in the open

If something goes wrong we tell you within twenty-four hours of confirming it, with what we know, what we have done and what happens next. We do not wait to have a complete story before we make the first call.

Security is reviewed on a calendar, not after an incident.
  1. Quarterly review

    Every quarter we review access, keys, dependencies, backups and the incident log against the controls on this page, and close what we find with a name and a date.

  2. Independent test, every year

    An independent penetration test of the artifacts we operate, at least once a year and after any change to how they are exposed. Findings are fixed, retested, and the report is available to you under NDA.

  3. Your audit, our answers

    When your client or your auditor sends a questionnaire, we answer it. Controls are mapped to the framework they ask about, with evidence, in writing.

  4. Improvement is the default

    Every finding, ours or yours, becomes a change with an owner and a deadline. This page is updated when the controls change, with the date at the top.

Built against the frameworks your auditor already uses.

Our controls are designed and mapped against ISO/IEC 27001, the SOC 2 trust services criteria, the OWASP Application Security Verification Standard and the NIST Cybersecurity Framework. We say exactly which controls are certified by a third party and which are attested by us, per engagement, in writing. We do not use a framework’s name to imply a certificate we do not hold.

  • ISO/IEC 27001 controls
  • SOC 2 trust services criteria
  • OWASP ASVS
  • NIST Cybersecurity Framework
Found something? Tell us.

If you believe you have found a vulnerability in anything we operate, write to us through the contact form with the details and how to reproduce it. We acknowledge within two business days, keep you informed while we fix it, and credit you if you wish. We will not take legal action against research done in good faith.

Next

Connect us with one of your experts.

Your people keep the judgment. Lucum turns their rules and exceptions into a tool the company owns.