Security

Security you can show your auditors

Financial data requires the highest standard of protection. Lumio360 is built with security as a design constraint, not an afterthought.

SOC 2 Type II pending
ISO 27001 pending
GDPR Compliant
UK GDPR Compliant
How we protect your data

Security practices

Every layer of Lumio360 — from data transfer to access control — is designed to meet the expectations of finance teams with strict compliance requirements.

Data encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys are managed separately from encrypted data.

Access controls

Role-based access with least-privilege enforcement. Multi-factor authentication available for all accounts. SSO support available on request.

Audit logging

Every action in Lumio360 — journal posts, approvals, logins, exports — is logged with timestamp, user, and IP address. Logs are immutable and retained for 7 years.

Infrastructure

Hosted on leading cloud infrastructure with redundancy across availability zones. 99.9% uptime SLA.

Penetration testing

Independent penetration testing conducted annually. Findings are remediated before the next release cycle.

Data residency

Responsible disclosure

Found a vulnerability?

If you discover a security vulnerability in Lumio360, please report it to security@lumio360.com. We acknowledge reports within 48 hours and aim to resolve critical issues within 7 days.

Report a vulnerability
Get started

Ready to move your close to a secure platform?

Book a demo and we will walk through Lumio360's security controls alongside your close process.

Book a demo