A Multi-Layered Approach to Security
At Lumin Digital, security isn’t just a feature—it’s a foundational principle. Since day one, security has been deeply embedded into every layer of our platform, ensuring a resilient, proactive, and scalable approach to protecting our clients and the people they serve.
A Culture of Security
We don’t just rely on tools—we empower every team, from development to operations, to think security-first. By integrating security at every stage of our product development and fostering deep awareness across our organization, we ensure that protection isn’t an afterthought but an inherent part of everything we do.
Hardened Infrastructure & Automated Resilience
Built entirely on a cloud-native architecture, Lumin operates with a zero-trust mindset, enforcing strict security controls while maximizing efficiency. Our automation-driven infrastructure enables weekly releases without sacrificing security, ensuring rapid updates, patching, and consistency across thousands of servers. Our environments are continuously refreshed with infrastructure-as-code, eliminating configuration drift and reducing risk exposure.
Secure Application Development & Advanced Threat Protection
Security is seamlessly woven into our software development lifecycle, with rigorous secure coding practices, real-time monitoring, and automated anomaly detection. Our Security Operations Center (SOC) continuously analyzes threats, leveraging industry intelligence from FS-ISAC and other cybersecurity partners to stay ahead of emerging risks.
Adaptive Fraud Prevention & Intelligent Authentication
Lumin employs machine learning-driven fraud detection, behavioral analytics, and adaptive authentication to defend against threats proactively. We were early adopters of passkeys and continuous authentication, ensuring secure and frictionless user experiences. Our enterprise-grade bot management and API security measures also provide robust perimeter protection against automated attacks.
Transparent Compliance & Client Collaboration
We exceed industry standards with SOC 2 Trust Services Criteria, PCI Data Security Standard, and GLBA-aligned security frameworks, all transparently documented in our client-accessible GRC platform. We believe in open collaboration, offering real-time security insights, direct client engagement, and continuous improvements to meet evolving regulatory and security challenges.
At Lumin, security isn’t just a responsibility—it’s our passion. Through a culture of security, cutting-edge automation, and continuous innovation, we provide the highest protection, resilience, and trust in digital banking.
Reporting
Please send an e-mail to [email protected] along with details that permit us to fully understand the issue you are observing, and if possible, with screenshots, logs, URL’s with parameters, sample output, or steps to reproduce the issue that we can use to validate your report and identify the root cause. Please also provide information that allows us to respond to you for additional questions, and, to the extent we can, to apprise you on our progress in resolving the issue. If possible, please provide your IP address to allow us to correlate your activity in our logs for further diagnosis.
You may send us encrypted emails by using our public PGP key and please do so if any information you send is confidential. We have published our key on public key servers and you will also find it reproduced below:
—–BEGIN PGP PUBLIC KEY BLOCK—–
xsFNBGZEzrABEACs6dwq/ZQlD1hQYMoJpws59Je7fJS00FoMnPZ6z6BCmPg6wBL9VXmaaycSHsnfHDGOhUAJd504Py+6EAuq8NSkndjyIK7euwDBiOe8wQDjtx2LTlO2GaaPDYME9wMUrpc1AeffajBPmKqz8qSlzQ06CbY5ucdwwiihKupDAttpKnrN3pJ7k2cBMM/kUFvdd7AP0JvSa59OddSJ7sY2auH7FeSLIjlq524IswDtOsYBAsfs4X5I7ZslQzSVN4sZJwWWlsTfUjgc7Fh7jLni0bAgk2t3ELqFE5x4J2Ax9sVl0PZfhvWMMKSGUh+keLUyHi5gKqFBXlLN481ZeXlZEgA/SIv/FetCi0QqxZ1blVLj1jAFDR/7V3IqqtKdF3RAlIalnz/bv2ZebNHwC81MqPXQpWD9b99L7GESSdFm63P8110laTEb8NbCObJr9OFtkOUK2rVCneNncOLfBrWxL1HayRty5nIGow0RZBQr2NxhqVGmBN1HSnv1MMpMGtB49+m31il0Nupdnn/A9Rynx45VcRizMakt/ke19oXQyCe+4SUymJHbZupNvuG5sLC2vdxT2Py09FunsezlJUEYk02Q9Np86DNy8A3BvHdn9CDiWysrCyyNblMJHBBFQUhGgGPvYFufEgEm0n6i4IR5V+HQ+eoqaxdRSGAlESMniHRJfwARAQABzTpTZWN1cml0eSBEaXNjbG9zdXJlIDxzZWN1cml0eS1kaXNjbG9zdXJlQGx1bWluZGlnaXRhbC5jb20+wsGKBBABCAA+BYJmRM6wBAsJBwgJkPTYnDgLljoNAxUICgQWAAIBAhkBApsDAh4BFiEEhmva4wqshK3WxHOu9NicOAuWOg0AAH5nD/4qvvTu/VEGjmQTks+SkOGGhR/wCPDOp62HBIi5JBvCTt3WbtSB6DsXc7BHDFol4AaBtV4VZa/LIt2NjirsRUBXJzi3n4icxQ8L3y6GrNIvs+SK7p7sqB/giZT/kcUAQSKyQBI2EZwa1NYRy88WxDzHmPoXOtZTEOJHGRIk1gvtlRF/HkzSb0QjQplD2nO//kct1vz4mqm0PWd0tEbcMRE0Rfqy8wbYqXhodIobajT/rFySfdDnK19FzsgiRD8crKrkD7zCB89wdqXfKkv9poaz+pnDijX1oaY6WjSkfhAGtJ6vmbBlP1zQdMBkFl64Xk7OlE1H8Kg3YLkjAJMKxrpRcApYRzwlBrXDaOEXSsllhXr+gtI2lvLoAG84cw1LDU2kzcwWktycW17Fzrb5y5tKCmdmn/gVAd+HnKmpAzbQQT7V8ok28xnb9aKf8rOoAqRcGxBM4PlUxCOcFWRHrGEQSVO8+2Nn0WzfZ+1vltEEm0LbCrlC6s6SuVEj1DJ8WgQHCVdOkt8PG0ZDsrOAEeHm3SfgpAn12bmT2s5cL6GXn3+eYqPkrUuzLGe8Qh/OUSXwRYv2i9uCFdiSRjy46JGBEWWHQY4ZcXZ8b1tni9dovAzHi83cFQXGa+qseCTtkxOdHKN+hi86gOmIIKJx57HZBRjYROiF1RvVsrpHUeYwE87BTQRmRM6wARAAp2fHsW7cZu57qzj1E/RPPWanHE3eXtHWxOcO6/Sb0kRMS+zUI8J9VD+GfYHPgPNFePZfhD0KPYppwOB9B7oKgPzK5rXf61UwE5WFIkeRnl2+2jEJOW5O7hl6kXUsKW35AoSaMKpueoR1WNkgdHGQTpM4B20WTX+4EUyzijK4LYxEKeQnOG8ICJgKQU1t3pbSJ5rR5KySeF+W+bCnUuQBADxd3Iab3rDDABgiywlG1alrc6NqI8S+c829iIK9MexLRPfOcriSX6wuE5UbR54IddkGSWVsr+CUql5xdpbvaA8kKd3Yvu/74SYY2ZbPZbC6KQqXRIDE56qURpAwIuVvFp2DJwsrBozECQsjfg5DnCwuQn4QzI0HTUecxi1Bay7rRTW1Pb4Dzop8M4uxiM8Jw0wqUntREDIeiQVyMriU4aQLeYPOqWX3zTsyAO1inZPsNGT6BD0H4bgxcCn/71KPQgMYmT4mQXScrh2bQcLOqGcKTF4vAM/RRInhCZ6obh/p9B/GNDSxzyzbTUbsBOCmruIivQ7HD2UtYQ7cY8Mq3hHSPNrWlEKZvHfMLa+dBDCfrZ7euSLbo2P7ej4jh8ksh6gLMfoNMJh30mweiUjGRnsUL2t090ZW3+SsBfEl1WrGmtgdVoBpUDjqFMqaaZna7olN1DbP+8Nu8dXKHgqS50UAEQEAAcLBdgQYAQgAKgWCZkTOsAmQ9NicOAuWOg0CmwwWIQSGa9rjCqyErdbEc6702Jw4C5Y6DQAAVBUP/22EWkdiiuClEtiXZnIL1zktHQ6POzA1ih1xfNFom/E8v6eXiwnli3xFst1eyxoT7wdUwmS/fWGJPx9k6aRmcp3YkzrV/Pi6kyH2TfZkmatwwwa8OW3ULoItrTDIgXzz0qcq/3hXBLfDKrNHerMBdF+ILCa0KHhydNE0xfpuOras21MWWjsV3tJHrfiKip2LDjB6BNL261niduNRuojCdfwNlSxSZS6xpl6febP2qc9QglWeKv/juwh3V8NEx6J1qYF6R0gw9hzpAPAFpK/Wxw7XLsuKnENC/DkrWf3q4pp2if9s9s25mbrbo6aDLg2c0j5JKleMBnwnTvHyg6gI3CyKlsMSdny1jwU7EbvUpH/bZV4u9lO9QXmTYBwxHsNQRCkFAfSbfb551Y63vPEKOMwatkuwCfcQsHY8lw+PbkA9cLaE9CtUTGVGD9rZO5KqK2PaHzBlS/oHcr3fTv73QSRWu0Exo80nHb1Nv1+OwaOP/SEmaHKHEKnppX/VsytR6NCTkTxPohII3NhXyaz6qWGvqz3kfHwPl8WEPa6WJ1UG3QG0LO9KhqJ/qa7dTbCvekQvjS4g7kZmX3CUrYEegKfCUZWqGKUbDCZWPB8nMxyLwQW6Ni6PaPTX72x0/RoO+eJ/RcNsJenAkVRudw3Jz0hA3Qi9sxa7qhz0+/8W4BAL=Ghp7
—–END PGP PUBLIC KEY BLOCK—–
Acknowledgements
- Mehul Bharat Lunagariy
- Yash Vilas Chavhan
- Bhaskar Tejaswi
- Nikhil Rane
- Gourav Sankalle