We build Lumen for regulated industries. Security and data integrity are foundational to everything we do.
Lumen is a multi-tenant platform with strict data isolation. Every table includes an organisation identifier, and Row-Level Security policies enforce that users can only access data belonging to their own organisation. This isolation operates at the database level, independent of application logic.
When AI features are used (content generation, teaching assistance), we apply anonymisation measures before sending data to AI providers. No personally identifiable information is sent to third-party AI models. AI providers (Anthropic, OpenAI) are bound by data processing agreements and do not use our data for training.
If you discover a security vulnerability in Lumen by RegNexus, please report it responsibly to security@reg-nexus.com. We will acknowledge receipt within 24 hours and work to resolve verified vulnerabilities promptly. We ask that you do not publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.