Security & data handling
Agencies trust Luminous Social with client marketing data. Here is how we protect it — written for founders and IT reviewers, not lawyers.
Encryption in transit & at rest
Traffic uses TLS. Client credentials and tokens are stored in encrypted databases with restricted access.
Least-privilege access
Team roles (owner, admin, member) control who can manage clients, billing, and content. Clients only see their portal or approval links.
Your data stays yours
We pull metrics from connected platforms to generate reports. We do not sell client data or use it to train public AI models.
Infrastructure
App hosting on Vercel. Data and auth via Supabase. Payments via Stripe. Transactional email via Resend.
Compliance posture
SOC 2 Type II is in progress. We align practices with GDPR expectations for processors handling EU personal data on behalf of agencies.
OAuth, not password sharing
Integrations use OAuth or API keys you control. Disconnect anytime from the client or Integrations page.
Questions or incidents
Email help@luminoussocial.com for security questions or to report a vulnerability. See also our Privacy Policy and Terms.