Skip to content

Trust

Security & data handling

Agencies trust Luminous Social with client marketing data. Here is how we protect it — written for founders and IT reviewers, not lawyers.

  • Encryption in transit & at rest

    Traffic uses TLS. Client credentials and tokens are stored in encrypted databases with restricted access.

  • Least-privilege access

    Team roles (owner, admin, member) control who can manage clients, billing, and content. Clients only see their portal or approval links.

  • Your data stays yours

    We pull metrics from connected platforms to generate reports. We do not sell client data or use it to train public AI models.

  • Infrastructure

    App hosting on Vercel. Data and auth via Supabase. Payments via Stripe. Transactional email via Resend.

  • Compliance posture

    SOC 2 Type II is in progress. We align practices with GDPR expectations for processors handling EU personal data on behalf of agencies.

  • OAuth, not password sharing

    Integrations use OAuth or API keys you control. Disconnect anytime from the client or Integrations page.

Questions or incidents

Email luminoussocialhelp@gmail.com for security questions or to report a vulnerability. Check system status for uptime. See also our Privacy Policy and Terms.