Security & Trust

Enterprise-grade security, compliance, and transparency for AI-powered customer experience.

Built for contact centers, BPOs, and regulated industries that require real accountability.

✓ A2P Brand & Campaign Verified ✓ SHAKEN/STIR Approved ✓ Voice Integrity Approved ✓ Wisconsin Trademark: Lumina CX OS & AI Ops Pro ⏳ SOC 2 — In Progress
Core Security Commitments

We take a security-first approach to every layer of the Lumina CX OS platform.

  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access control with multi-factor authentication (MFA)
  • US-based data processing
  • No sale of customer data — ever
  • Clear AI disclosure on every Sophia interaction
  • Human escalation always available
  • Continuous health monitoring and incident response
Infrastructure & Architecture

Lumina CX OS is built on a modern, multi-layered architecture designed for reliability and security.

  • Voice AI layer powered by leading enterprise-grade infrastructure with GPT-4.1 class models
  • CRM and workflow automation hosted on an enterprise-ready platform
  • Automation and integration layer with secure webhook validation
  • Telephony with full A2P registration, SHAKEN/STIR, and Voice Integrity
  • All administrative access protected by MFA and least-privilege principles
  • Current subprocessor list available under NDA upon request
Compliance & Certifications

Currently Active

  • A2P Brand Registration Approved
  • A2P Campaign Verified
  • SHAKEN/STIR Approved — July 2026
  • Voice Integrity Approved — July 2026
  • Wisconsin State Trademarks — Lumina CX OS & AI Ops Pro

In Progress

  • TCPA & FCC AI Voice/SMS compliance review with outside counsel In Review
  • SOC 2 Type I Roadmap Underway
  • Enhanced AI governance documentation In Progress

We are happy to share our current compliance roadmap and timeline with qualified prospects under NDA.

Data Protection & Privacy

Your data belongs to you. We act as a processor and follow strict principles.

  • Encryption of data in transit and at rest
  • Clear data retention schedules for call recordings, transcripts, and CRM records
  • Customer-initiated data deletion and export capabilities
  • No training of foundation models on your proprietary customer conversations without explicit agreement
  • US data residency for core processing
  • Full Privacy Policy and Data Processing Addendum (DPA) available

Request our DPA: [email protected] or via your account team.

Access Control & People Security
  • Multi-factor authentication (MFA) enforced for all administrative users
  • Role-based access control (RBAC) — least privilege by default
  • Regular access reviews
  • Secure employee offboarding procedures
  • Security awareness expectations for all team members with platform access
Monitoring, Reliability & Incident Response

We operate a multi-layered health monitoring system.

  • Synthetic probes and real-time workflow failure detection
  • Automated alerting to our operations team
  • Documented Incident Response Playbook with clear severity levels and escalation paths
  • Post-incident review process

A public status page is part of our near-term roadmap. Enterprise customers receive proactive notifications for any material incidents affecting their instance.

AI-Specific Trust & Transparency

Sophia is an AI voice agent. We believe transparency builds trust.

  • Sophia clearly identifies herself as an AI assistant at the start of every call
  • Callers can request a human agent at any time
  • Critical or sensitive issues are escalated according to defined criteria
  • We do not hide the use of AI or synthetic voice
  • Customers retain control over prompts, routing logic, and escalation rules
  • We maintain human oversight policies and continuous improvement processes

Full details on our AI disclosure and human escalation practices are available in our compliance documentation.

Request Security Information

Enterprise and mid-market customers often need additional documentation. We are prepared to provide:

  • Completed security questionnaires (SIG Lite, CAIQ, or custom)
  • Data Processing Addendum (DPA)
  • Evidence of insurance (Cyber Liability & E&O)
  • Architecture and data-flow overview (under NDA)
  • Current subprocessor list
  • SOC 2 roadmap and timeline

To request a security packet or schedule a technical discussion:

Email: [email protected]

Subject line: Security Packet Request – [Your Company Name]