Lluminate Trust Centre

Trust & Security

We build and operate software for trade unions, charities and campaigning organisations, so we hold some of the most sensitive personal data recognised in law — trade union membership, health and genetic data, and data revealing political opinions. All of it is special category data under Article 9 of the UK GDPR, and our security is designed around that fact.

We take that responsibility seriously. This page sets out exactly how we protect it — what we hold, where it lives, who touches it, and what we will never do with it.

Request documents

Certifications

Cyber Essentials

Cyber Essentials

Certified
ICO registration

ICO registration

Registered Verify on the ICO register
UK GDPR and EU GDPR

UK GDPR and EU GDPR

Compliant

Documents

Response within 5 working days. No NDA required.

Information security and data protection policy summary
Data processing agreement
Completed security questionnaire responses
Business continuity and disaster recovery summary
Sub-processor list with full legal entity names and DPA status
Cyber Essentials certificate
Request from [email protected]

Controls

Access control

  • Role-based access control
  • Two-factor authentication (2FA)
  • Unique individual credentials
  • Time-bound production access
  • Quarterly access reviews
  • Documented leaver process

Every account uses unique individual credentials. Accounts are never shared. Multi-factor authentication is enforced on every service where it is available, without exception, using hardware security keys, passkeys or authenticator applications in preference to SMS.

Access is granted on a need-to-know basis and scoped to role. Access to client production data is not a standing permission: it is authorised in writing for a specific task, is time-bound with an explicit end date, and is logged. Access is reviewed quarterly against the current personnel list, and a documented leaver process disables all accounts on departure, rotates shared credentials and terminates active sessions.

Systems and patching

  • All software within vendor support
  • Automatic updates enabled
  • Critical patches within 14 days
  • Automated dependency scanning
  • Advisories triaged in two working days

All software in use is within vendor support. Automatic updates are enabled wherever available, and security updates rated critical or high are installed within 14 days of release, covering operating systems, applications and dependencies. Application dependencies are monitored by automated vulnerability scanning, with advisories triaged within two working days.

Network security

  • Default-deny traffic filtering
  • Documented, approved firewall rules
  • No internet-exposed databases
  • Key-based administrative access
  • Private networking between services
  • DNSSEC

Inbound traffic to our infrastructure is default-deny. Only the ports required to serve web traffic are open, each with a documented business justification and a named approver, reviewed at least annually. Databases and administrative interfaces are not exposed to the internet. Administrative access uses key-based authentication with password authentication disabled.

Endpoint security

  • Full-disk encryption
  • Always-on software firewall
  • Automatic updates and malware protection
  • Five-minute automatic lock
  • Version-controlled device configuration
  • DNS filtering

Every device used for Lluminate work runs full-disk encryption, an always-on software firewall, automatic updates and malware protection, and locks automatically after five minutes. Configuration is managed declaratively and version-controlled, so the installed state is auditable at any point in time.

Encryption

  • TLS 1.2 minimum, TLS 1.3 preferred
  • HSTS enabled
  • AES-256 at rest, including backups
  • Field-level encryption on special category data
  • Memory-hard password hashing

Data in transit is protected by TLS 1.2 as a minimum, with TLS 1.3 preferred and HSTS enabled. Data at rest, including databases and backups, is encrypted using AES-256. Special category fields in our registry platforms carry additional field-level encryption. Passwords are hashed using a memory-hard algorithm and are never stored in a recoverable form.

Application security

  • Separate dev, staging and production
  • Peer review before production
  • Second reviewer on sensitive changes
  • Automated secret scanning on every commit
  • Static and dependency code analysis
  • Database-per-tenant isolation
  • API authentication and rate limiting

Development, staging and production are separate environments with separate credentials. Every change is peer reviewed before it reaches production. Changes touching authentication, authorisation, encryption, tenant isolation or the handling of special category fields require review by a second person with relevant competence.

Secrets are never committed to repositories; automated secret scanning runs on every commit. Multi-tenant platforms maintain tenant isolation by design, with database-per-tenant separation on our patient registry platform.

Data security

  • Encrypted off-site backups
  • Backup credentials separate from production
  • Quarterly restore testing
  • Access monitoring and audit logging
  • Logs retained for 12 months
  • Managed password manager

Infrastructure

  • UK and EEA data centres only
  • Anti-DDoS protection
  • Web application firewall
  • Managed TLS termination and CDN
  • Isolated production environment

Corporate security

  • Documented incident response
  • Post-incident review within 10 working days
  • SPF, DKIM and DMARC on all sending domains
  • Annual security awareness training

Policies

  • Lluminate privacy note
  • Information Security & Data Protection Policy
  • Digital Sovereignty Policy
  • Impact Policy
  • Business Continuity & Disaster Recovery Plan

Insurance

  • Professional indemnity cover
  • Cyber liability cover
  • Public liability cover

What we don't do

Written into policy and into every contract we sign.

We never use production personal data in development or testing.

We never use client data to train or fine-tune AI models.

We never blend data across clients.

We never sell data, and we do not serve advertising.

We never use client data for our own purposes.

Where your data lives

United Kingdom and European Economic Area only.

Production hosting and databases Falkenstein, Germany
Encrypted off-site backups Helsinki, Finland
Remote administration United Kingdom and Spain

All processing takes place within the United Kingdom or the European Economic Area. The EEA is covered by the UK's adequacy regulations, so no additional transfer mechanism is required. Where a supplier is established outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses and record the transfer in the relevant data processing agreement.

Our backups are held under credentials separate from production and in a different physical location, so that compromise of our production environment cannot destroy them. Restores are tested quarterly and the test is recorded.

Map of the United Kingdom and European Economic Area. Lluminate data locations are marked at Falkenstein in Germany, Helsinki in Finland, the United Kingdom and Spain. Falkenstein Helsinki United Kingdom Spain
UK and EEA Countries we operate in Our locations

Sub-processors

Each engaged under a written DPA, diligenced before any data is shared, reviewed annually.

Hetzner Online GmbH logo

Hetzner Online GmbH

Cloud infrastructure hosting and encrypted backup

Germany, Finland

Amazon Web Services logo

Amazon Web Services

Compute and storage

European Union

Salesforce (Heroku) logo

Salesforce (Heroku)

Application hosting

European Union

Cloudflare, Inc. logo

Cloudflare, Inc.

DNS, TLS termination, CDN and web application firewall

Global edge network

Mailgun Technologies logo

Mailgun Technologies

Transactional email delivery

European Union

Twilio Inc. logo

Twilio Inc.

SMS delivery

European Union

Get notified of changes. We notify clients before adding a new sub-processor. To receive those notifications, email [email protected].

FAQs

If you have found a security issue in any Lluminate product, please tell us at [email protected].

We will acknowledge your report within 5 working days and keep you updated as we investigate. We will not pursue legal action against anyone who reports a vulnerability in good faith, does not access or modify data beyond what is necessary to demonstrate the issue, and gives us reasonable time to fix it before disclosing publicly.

We do not currently operate a paid bug bounty, but we are glad to credit researchers who would like to be named.

For most of our platforms, the organisation we work with is the data controller and Lluminate is the processor. We act only on their documented instructions.

If you are a member of a union, a participant in a patient registry, or otherwise an individual whose data sits in one of our platforms, the organisation running that service is responsible for your data and is the right place to direct a request. If you contact us, we will acknowledge you and pass your request to them within one working day.

For questions about our own processing, or to make a data protection complaint, contact [email protected]. We will acknowledge any complaint within 30 days and tell you the outcome without undue delay. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Lluminate is the trading name of The Mather Group Ltd, registered in England and Wales, company number 12587276. Registered office: Unit 312 Zellig Building, The Custard Factory, Gibb Street, Birmingham, B9 4AU.

Security and data protection are the responsibility of the director, Lluis Mather, who can be reached at [email protected].