Trust · Security · Responsible AI

Built so your data — and your AI — can be trusted.

The page to hand your compliance, procurement or IT team. How we handle client data, which suppliers touch it, how we approach model choice and guardrails, and where we stand on the regulation that applies to you.

Data handling, defined before anything is built

Every engagement starts by agreeing — in writing, in the statement of work — where data lives, who can access it, how long it is retained, and what leaves your environment. We build around your existing systems, identity and permissions (Microsoft 365, Google Workspace, your CRM, PSA or databases), so access follows the controls you already trust rather than a parallel copy of your data.

  • Residency: UK data residency is available where you need it; EU and US residency are agreed per engagement.
  • Least privilege: we ask for the minimum access that lets us do the work, and it is revocable by you at any time.
  • Your auth, not ours: production systems run behind your authentication, on your tenancy wherever practical.

Your data is not training material

We do not use client data to train models, and we configure the model providers we use so they don't either. Commercial API terms from the major providers (OpenAI, Anthropic, Google, AWS-hosted models) exclude API data from model training by default — we use those commercial routes, not consumer tools, and where a provider offers additional data-handling controls (zero-retention options, regional processing) we switch them on when the engagement calls for it.

Multi-model by design — governed by evals

We choose the model for the workload, not the vendor with the loudest marketing, and every route a workload can take is governed by evaluation suites — quality checks that run before any model change reaches production. Guardrails are engineered in from the first week: input validation, output constraints, human sign-off where the decision warrants it, and full traceability from answer back to source.

Who processes what

For this website, the processors are listed in our privacy policy (Cloudflare, Resend, cal.com, Microsoft). For client engagements, the subprocessor list is agreed per engagement in the statement of work — typically your own cloud tenancy plus the model provider(s) selected for the workload — and doesn't change without telling you.

Regulatory posture

  • UK GDPR / EU GDPR: Lumitec AI Ltd is registered with the ICO. Data processing agreements are in place with our suppliers, and we'll work within yours.
  • EU AI Act: most of what we build for business customers sits in the Act's minimal or limited-risk categories; where a use case approaches a higher-risk classification, we say so during the Diagnostic and design the transparency and oversight obligations in from the start — not as a retrofit.
  • Sector rules: where your industry brings its own requirements, those constraints go into the statement of work like any other engineering requirement.

Security practice

  • Encryption in transit everywhere; encryption at rest on the platforms we deploy to.
  • Access on a named-individual basis — you know exactly who at Lumitec AI can see what.
  • Secrets kept in managed secret stores, never in code or documents.
  • Production monitoring with alerting, and evals run before changes go live — reliability is a security property.

The honest limits

We are a senior, hands-on consultancy — not a hyperscaler with a certifications page. We don't claim accreditations we don't hold. What we will do is answer any security questionnaire directly, walk your IT team through the architecture before you commit, and put every commitment on this page into your contract. If that level of straight answer is what your procurement process needs, we'll get on well.

Questions? Ask us directly — a founder replies, usually within one working day.

Want the details for your use case?

Book a free, no-obligation call and bring your IT or compliance lead — we're happy to be grilled.

Book a free 30-min call →