Trust & Security
We build and operate software for trade unions, charities and campaigning organisations, so we hold some of the most sensitive personal data recognised in law — trade union membership, health and genetic data, and data revealing political opinions. All of it is special category data under Article 9 of the UK GDPR, and our security is designed around that fact.
We take that responsibility seriously. This page sets out exactly how we protect it — what we hold, where it lives, who touches it, and what we will never do with it.
Request documentsCertifications
Cyber Essentials
CertifiedUK GDPR and EU GDPR
CompliantDocuments
Response within 5 working days. No NDA required.
Controls
Access control
- Role-based access control
- Two-factor authentication (2FA)
- Unique individual credentials
- Time-bound production access
- Quarterly access reviews
- Documented leaver process
Every account uses unique individual credentials. Accounts are never shared. Multi-factor authentication is enforced on every service where it is available, without exception, using hardware security keys, passkeys or authenticator applications in preference to SMS.
Access is granted on a need-to-know basis and scoped to role. Access to client production data is not a standing permission: it is authorised in writing for a specific task, is time-bound with an explicit end date, and is logged. Access is reviewed quarterly against the current personnel list, and a documented leaver process disables all accounts on departure, rotates shared credentials and terminates active sessions.
Systems and patching
- All software within vendor support
- Automatic updates enabled
- Critical patches within 14 days
- Automated dependency scanning
- Advisories triaged in two working days
All software in use is within vendor support. Automatic updates are enabled wherever available, and security updates rated critical or high are installed within 14 days of release, covering operating systems, applications and dependencies. Application dependencies are monitored by automated vulnerability scanning, with advisories triaged within two working days.
Network security
- Default-deny traffic filtering
- Documented, approved firewall rules
- No internet-exposed databases
- Key-based administrative access
- Private networking between services
- DNSSEC
Inbound traffic to our infrastructure is default-deny. Only the ports required to serve web traffic are open, each with a documented business justification and a named approver, reviewed at least annually. Databases and administrative interfaces are not exposed to the internet. Administrative access uses key-based authentication with password authentication disabled.
Endpoint security
- Full-disk encryption
- Always-on software firewall
- Automatic updates and malware protection
- Five-minute automatic lock
- Version-controlled device configuration
- DNS filtering
Every device used for Lluminate work runs full-disk encryption, an always-on software firewall, automatic updates and malware protection, and locks automatically after five minutes. Configuration is managed declaratively and version-controlled, so the installed state is auditable at any point in time.
Encryption
- TLS 1.2 minimum, TLS 1.3 preferred
- HSTS enabled
- AES-256 at rest, including backups
- Field-level encryption on special category data
- Memory-hard password hashing
Data in transit is protected by TLS 1.2 as a minimum, with TLS 1.3 preferred and HSTS enabled. Data at rest, including databases and backups, is encrypted using AES-256. Special category fields in our registry platforms carry additional field-level encryption. Passwords are hashed using a memory-hard algorithm and are never stored in a recoverable form.
Application security
- Separate dev, staging and production
- Peer review before production
- Second reviewer on sensitive changes
- Automated secret scanning on every commit
- Static and dependency code analysis
- Database-per-tenant isolation
- API authentication and rate limiting
Development, staging and production are separate environments with separate credentials. Every change is peer reviewed before it reaches production. Changes touching authentication, authorisation, encryption, tenant isolation or the handling of special category fields require review by a second person with relevant competence.
Secrets are never committed to repositories; automated secret scanning runs on every commit. Multi-tenant platforms maintain tenant isolation by design, with database-per-tenant separation on our patient registry platform.
Data security
- Encrypted off-site backups
- Backup credentials separate from production
- Quarterly restore testing
- Access monitoring and audit logging
- Logs retained for 12 months
- Managed password manager
Infrastructure
- UK and EEA data centres only
- Anti-DDoS protection
- Web application firewall
- Managed TLS termination and CDN
- Isolated production environment
Corporate security
- Documented incident response
- Post-incident review within 10 working days
- SPF, DKIM and DMARC on all sending domains
- Annual security awareness training
Policies
- Lluminate privacy note
- Information Security & Data Protection Policy
- Digital Sovereignty Policy
- Impact Policy
- Business Continuity & Disaster Recovery Plan
Insurance
- Professional indemnity cover
- Cyber liability cover
- Public liability cover
What we don't do
Written into policy and into every contract we sign.
We never use production personal data in development or testing.
We never use client data to train or fine-tune AI models.
We never blend data across clients.
We never sell data, and we do not serve advertising.
We never use client data for our own purposes.
Where your data lives
United Kingdom and European Economic Area only.
All processing takes place within the United Kingdom or the European Economic Area. The EEA is covered by the UK's adequacy regulations, so no additional transfer mechanism is required. Where a supplier is established outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses and record the transfer in the relevant data processing agreement.
Our backups are held under credentials separate from production and in a different physical location, so that compromise of our production environment cannot destroy them. Restores are tested quarterly and the test is recorded.
Sub-processors
Each engaged under a written DPA, diligenced before any data is shared, reviewed annually.
Hetzner Online GmbH
Cloud infrastructure hosting and encrypted backup
Germany, Finland
Amazon Web Services
Compute and storage
European Union
Salesforce (Heroku)
Application hosting
European Union
Cloudflare, Inc.
DNS, TLS termination, CDN and web application firewall
Global edge network
Mailgun Technologies
Transactional email delivery
European Union
Twilio Inc.
SMS delivery
European Union
Get notified of changes. We notify clients before adding a new sub-processor. To receive those notifications, email [email protected].
FAQs
If you have found a security issue in any Lluminate product, please tell us at [email protected].
We will acknowledge your report within 5 working days and keep you updated as we investigate. We will not pursue legal action against anyone who reports a vulnerability in good faith, does not access or modify data beyond what is necessary to demonstrate the issue, and gives us reasonable time to fix it before disclosing publicly.
We do not currently operate a paid bug bounty, but we are glad to credit researchers who would like to be named.
For most of our platforms, the organisation we work with is the data controller and Lluminate is the processor. We act only on their documented instructions.
If you are a member of a union, a participant in a patient registry, or otherwise an individual whose data sits in one of our platforms, the organisation running that service is responsible for your data and is the right place to direct a request. If you contact us, we will acknowledge you and pass your request to them within one working day.
For questions about our own processing, or to make a data protection complaint, contact [email protected]. We will acknowledge any complaint within 30 days and tell you the outcome without undue delay. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
Lluminate is the trading name of The Mather Group Ltd, registered in England and Wales, company number 12587276. Registered office: Unit 312 Zellig Building, The Custard Factory, Gibb Street, Birmingham, B9 4AU.
Security and data protection are the responsibility of the director, Lluis Mather, who can be reached at [email protected].