Skip to content
Skip to content

Security

For the most sensitive mandates

For the most sensitive mandates

For the most sensitive mandates

For the most sensitive mandates

Lunon keeps your client material safe with enterprise-grade security and data privacy controls.

Enterprise-grade protection

Purpose-built security

Purpose-built security

Security is owned by Lunon’s founding engineering team. Every internet-facing service is scanned weekly, every deploy is checked for vulnerable dependencies and images, every change is scanned for secrets, and every finding carries a remediation deadline.

Data sovereignty and control

Data sovereignty and control

You decide what enters an engagement. Material is scoped to that engagement, hosted in the United States, retained only for the life of the work, and returned or deleted at close on your instruction.

No model training

No model training

Lunon does not use your documents, data, or deliverables to train models. Our model providers are contractually bound to zero data retention and no training, and those terms are checked before any engagement runs.

Engagement isolation

Engagement isolation

Every engagement is its own boundary. Isolation is enforced at the database layer, access is limited to the team on your engagement, and every access is written to an append-only audit trail.

Enforceable commitments

Enforceable commitments

Every engagement begins under NDA. Our agreements carry binding terms on confidentiality, data handling, deletion at close, and no training, aligned with the SOC 2 Trust Services Criteria.

Independently audited

Independently audited

Lunon holds a SOC 2 Type I report, with the Type II observation period underway. Controls are monitored continuously, and the platform undergoes regular penetration testing and full-stack security audits, with findings remediated to closure.

Enterprise-grade security and controls

Enterprise-grade security and controls

Enterprise-grade security and controls

Lunon is built on a non-negotiable principle: the confidentiality of the material clients share with us. The platform was designed from the first commit to protect the most sensitive information in a transaction.

SOC 2 Type I

SOC 2 Type I

SOC 2 Type I

Lunon’s controls are audited against the AICPA Trust Services Criteria for security, availability, and confidentiality, and the Type II observation period is underway. The report is available to clients and prospects under NDA.

TRUST SERVICES CRITERIA IN SCOPE

Security

Systems are protected against unauthorized access, disclosure, and damage.

Availability

Systems are available for operation and use as committed and agreed.

Confidentiality

Information designated as confidential is protected as committed and agreed.

Security is fundamental to everything we do

We built one system that protects client material at every level, from identity and tenant isolation to scanning, auditing, and deletion. The controls are tested continuously and remediated on a clock, so the trust clients place in us is earned every week, not once a year.

Start with the decision in front of you.

Tell us what your team needs to understand, evaluate, or deliver.