Two kinds of data

Two kinds of data, two different protections

Your participants’ identities

Names and contact details of the people you serve are the most sensitive data you hold, and often legally protected. Our answer: we’re built so we don’t hold them in any form our team can read.

Your organizational strategy

Your grant pipeline, briefs, and financials are competitively vital, and you need us to work with them. Our answer: least-privilege access you can watch.

Participant identities

The participant identity vault Live today

When someone fills out one of your forms, any identifying fields are split off at the moment of collection into a separate identity vault, and the working record gets a code (like P-4X7K2). Everything downstream — analysis, reporting, drafting — runs on codes.

Intake screening

The intake gate Live today

Good rules need enforcement, so the platform screens everything on the way in. Every request, note, and file upload is checked server-side for participant-identifying patterns — lists of names, SSNs, date-of-birth columns, contact-sheet spreadsheets. Flagged items are rejected before anything is stored: nothing lands, even briefly. The rejection explains what was detected and shows the right path (coded forms, or a de-identified re-upload). PDF and image files can’t be content-screened, so uploading one requires you to confirm it contains no participant-identifying information — an honest limit, stated at the moment it matters.

Least-privilege access

Who can see your strategy

  • Assignment-scoped access Rolling outaccess will narrow to the operator(s) assigned to your organization, so unassigned staff are denied before your data loads. Today, access to your strategy is limited to Luminary’s own delivery personnel under confidentiality obligations — never offshore staff.
  • Audited overrides Rolling outan administrator override will be flagged, logged, and visible, never silent.
  • Reads, recorded Rolling outwe’re instrumenting a metadata record of each read of your briefs — who, what, when, never the content. Today your portal’s Activity view shows the actions taken on your requests (submitted, produced, delivered, approved); the full read log is being surfaced there as it rolls out. We won’t call it an access log until it is one.
  • Strict isolation Live todayyour data never informs another client’s work. The AI drafting context for your requests is assembled from your data only.
How we use AI

How we use AI (and how we don’t) Live today

Infrastructure

Where your data lives

Our platform runs on Supabase (database) and Vercel (application), encrypted in transit and at rest — the same class of infrastructure behind most modern software you already use. We’re not “in-house” — and honestly, neither are the spreadsheets, form tools, and email your data lives in today. The real question is whose controls are stronger. Ours are listed on this page, and they’re verifiable. If a funder requires your data to live somewhere specific, tell us — we’ll structure around it, working only from coded or aggregate exports. We’d rather narrow scope than put your funding at risk.

Portability

Leaving is easy (on purpose)

The honest limits

Trust built on overstatement isn’t trust

Two things we want you to understand precisely, because trust built on overstatement isn’t trust:

  1. Access separation, not client-held encryption. Database rules make the vault unreadable by our roles and our code paths — but our infrastructure necessarily includes a server-side service role that database rules don’t bind, restricted to our own server code. We claim “our people and our systems can’t read it,” and we verify that by query. We do not claim “mathematically no one could.”
  2. Different walls, different strengths. The identity vault is enforced at the database (live today). Operator assignment scoping will be enforced in the application with a database backstop (rolling out). We tell you which is which, and what’s live today versus coming.
The paper behind this page

Every claim here is backed by a contract you sign

A Data Processing Agreement (data classes, prohibited uses, a 72-hour breach-notification commitment, deletion schedules), an AI Disclosure, an Acceptable Use Policy, and — for HIPAA covered entities — a Business Associate Agreement. Our current subprocessor list is public. Ask us for any of it before you sign anything.

Questions, or want the Security & Compliance overview for your board or auditor? support@lilxhub.com.