Two kinds of data

Two kinds of data, two different protections

Your participants’ identities

Names and contact details of the people you serve are the most sensitive data you hold, and often legally protected. Our answer: we are built so we do not hold them in any form our team can read.

Your organizational strategy

Your grant pipeline, briefs, and financials are competitively vital, and you need us to work with them. Our answer: least privilege access you can watch.

Participant identities

The participant identity vault Live today

When someone fills out one of your forms, any identifying fields are split off at the moment of collection into a separate identity vault, and the working record gets a code (like P-4X7K2). Everything downstream, analysis, reporting, and drafting, runs on codes.

Intake screening

The intake gate Live today

Good rules need enforcement, so the platform screens everything on the way in. Every request, note, and file upload is checked server side for participant identifying patterns, such as lists of names, Social Security numbers, date of birth columns, and contact sheet spreadsheets. Flagged items are rejected before anything is stored. Nothing is retained, even briefly. The rejection explains what was detected and shows the right path (coded forms, or a de-identified re-upload). PDF and image files cannot be content screened, so uploading one requires you to confirm it contains no participant identifying information.

Least-privilege access

Who can see your strategy

  • Assignment scoped operator accessAccess to your strategy is limited to the Luminary delivery personnel assigned to your organization, under confidentiality obligations. Unassigned staff are denied before your data loads.
  • Audited overridesAn administrative override is flagged, logged, and visible. It is never silent.
  • Reads, recorded Rolling outA recorded data access log: a metadata record of each read of your briefs and strategy (actor class, data class, timestamp, never the content), surfaced to you in your portal. This is rolling out. Today your portal shows the actions taken on your requests, and says so plainly.
  • Strict isolationYour data never informs another client’s work. The AI drafting context for your requests is assembled from your data only.
How we use AI

How we use AI, and how we do not Live today

Infrastructure

Where your data lives

Our platform runs on a small set of United States based providers, each named in our public Subprocessor Disclosure:

We are not in house, and honestly, neither are the spreadsheets, form tools, and email that most organizations’ data lives in today. The real question is whose controls are stronger. Ours are listed on this page, and they are verifiable.

Subpoenas and legal demands

What a legal demand can, and cannot, reach

Nonprofits serving vulnerable people worry about legal process reaching participant identities. Our architecture is built to limit that exposure.

If we receive a legal demand touching your data, we notify you where the law allows, so your counsel can respond.

Portability

Leaving is easy, on purpose

Our security posture

Where we are on certification, stated directly

We are an early stage company. We do not have a SOC 2 attestation yet, and we will never imply that we do. Our platform is built on SOC 2 aligned architecture, and a formal audit is on our near term roadmap.

Here is what we do have today:

The full controls register, with an honest status on every control, is our Client Portal Security Program. We will complete your security questionnaire on request: support@lilxhub.com.

The honest limits

Two things we want you to understand precisely

Trust built on overstatement is not trust. So we state our limits plainly.

  1. Access separation, not client held encryption. Our protections are access separation, enforced at the database and application layers. Our infrastructure necessarily includes a server side service role that database rules do not bind, restricted to our own server code. We claim that our people and our systems cannot read your participant identities, and we verify that by query. We do not claim that mathematically no one could.
  2. Different walls, different strengths. The identity vault is enforced at the database. Operator scoping is enforced in the application with a database backstop. We tell you which is which, so you know exactly what stands behind each control.
The paper

Every claim here is backed by a document you can read

No form, no email wall. These are public. A Business Associate Agreement is available for HIPAA covered entities on request.

Data Processing Agreement

Data classes, prohibited uses, a 72 hour breach notification commitment, and deletion schedules.

Download (PDF)

AI Disclosure and Consent

Exactly what our AI touches, and what it never touches.

Download (PDF)

Acceptable Use and Data Submission Policy

The coded-data rule and how participant information may enter the platform.

Download (PDF)

Subprocessor Disclosure

Every provider that may process client data, what each can reach, and our 30 day change notice.

Download (PDF)

Also in the legal family: our Terms of Service, Privacy Policy, and the Client Portal Security Program.

Contact

Security questions and responsible disclosure

For security questions, a security questionnaire, or a copy of any document above, write to support@lilxhub.com.

If you believe you have found a security vulnerability, please report it to support@lilxhub.com with enough detail to reproduce it. Please do not access, alter, or exfiltrate any data beyond what is needed to demonstrate the issue, and give us a reasonable window to respond before public disclosure. We will acknowledge your report and keep you updated as we investigate.