1. Purpose and limits
This overview describes security principles and contracting expectations. It is not a security certification, audit report, service-level commitment, penetration-test result, or warranty. Customer-specific commitments must appear in a signed security exhibit or Order Form.
2. Shared-responsibility model
LumiTalk is responsible for safeguards within the contracted Services. Customer remains responsible for endpoint security, user lifecycle, credentials, identity provider settings, connected systems, permissions, lawful data selection, workflow configuration, and prompt or content supplied by Customer.
3. Identity and access
- Use unique accounts and least-privilege permissions where supported.
- Protect secrets and credentials in approved configuration channels rather than messages or prompts.
- Remove access promptly when roles change.
- Review connected-system scopes before enabling actions.
4. Data protection
The parties should define data categories, locations, encryption expectations, key responsibilities, retention, backup, export, deletion, and regulated-data restrictions in signed documents. No public marketing page expands the data types authorized for a customer deployment.
5. Secure operations
- Change and release controls appropriate to the service.
- Logging and monitoring proportionate to security and troubleshooting needs.
- Vulnerability intake, triage, remediation prioritization, and dependency review.
- Backups, recovery planning, and service continuity appropriate to the contracted service.
6. Incident response
LumiTalk should maintain procedures to identify, contain, investigate, remediate, and document security events and to provide contractual notices where required. Exact notification deadlines and content are contractual choices and are not promised by this page.
7. Providers and integrations
Cloud, communications, AI, analytics, scheduling, and customer-selected integration providers may participate in delivery. Their outages, API changes, regional availability, and independent processing create shared dependencies that must be addressed in the applicable agreement and subprocessor disclosure.
8. Assurance materials
LumiTalk will not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, GDPR, CCPA, penetration testing, or a defined uptime level until the specific evidence and scope are verified. Customers may request current available materials through the contact page.
9. Customer deployment checklist
- Classify the workflow and data before connection.
- Use the minimum permissions and data required.
- Test authorization failures, unsafe requests, unavailable systems, and human escalation.
- Define retention and audit evidence.
- Review the deployment after material changes.
10. Report a security concern
Use the Vulnerability Disclosure Policy for good-faith security research. For suspected account compromise or customer-data exposure, use the customer’s established support or incident channel rather than a public form whenever available.





