Security
When Lumify connects to CRM, accounting, email, or customer systems, access is a buying question—not an afterthought.
Your data stays under your control
We use secure, scoped access to connect with your existing systems. We don’t need employee passwords. Solutions can run in Lumify-managed infrastructure or your own cloud environment.
How access works
- OAuth where the platform supports it, so access is granted by an administrator and can be revoked.
- Scoped API credentials limited to the objects and actions the workflow requires.
- Service accounts instead of personal logins whenever the system allows it.
- Least privilege — no broader access than the specific workflow needs.
- Encrypted secrets for credentials stored in the runtime environment.
- Logging and monitoring so unusual activity can be reviewed.
- Client-owned infrastructure when you want the workload inside your cloud account.
What we do not do
We do not ask employees for passwords. We do not use your data to train public models. We do not keep access after an engagement ends unless you ask us to keep operating the system.