Trust Center

Security, privacy & trust at AskLumo

Everything your procurement and security teams need in one place. AskLumo is an AI assistant on top of Salesforce: it reads your org's metadata and records (always within your permissions) to answer questions, review access, and analyze reports. It never changes anything on its own: any change to Salesforce is explicitly initiated and approved by an authorized user, previewed, and audited. AskLumo is hard-isolated per tenant and contractually barred from training any AI model on your data.

No autonomous writes
Every change is human-approved & audited
Enforced
Tenant-isolated
Per-tenant process + storage, scoped in code
Enforced
Zero-training
Anthropic contractually barred
Guaranteed
Zero-inbound
Private VPC, no public ingress
Enforced
Compliance posture
Where AskLumo stands today, stated honestly. Several controls are inherited from our infrastructure subprocessors, and our own SOC 2 is planned for 2026.
SOC 2
Planned for 2026
CloudPrism's own report planned for 2026. Infrastructure is already SOC 2 Type II via AWS, Anthropic & Salesforce.
GDPR
Supported
Deletion on request; DPA available
ISO 27001
Inherited (AWS)
Underlying infrastructure
AWS FSBP
Active
200+ continuous controls in Security Hub
How AskLumo connects & handles data
The architecture your security team will want to understand, in plain terms.
Reads within your permission ceiling
AskLumo reads your Salesforce metadata and records to answer questions, review access, and analyze reports. Every read runs as your integration user, so its Field-Level Security is the hard limit on what AskLumo can ever see. It never changes anything on its own.
Per-tenant isolation
Each customer runs on a dedicated application process, a tenant-scoped S3 prefix, and DynamoDB access scoped to your tenant ID in code. Cross-tenant reads are blocked by design and deployment layout. Shared authentication tables hold only session and user records, not your org data.
Changes are governed, never autonomous
The AI never writes on its own. Any change to Salesforce is initiated and approved by an authorized user, previewed before it is applied, and written to an audit log. Metadata build and deploy (where AskLumo generates and deploys Apex, objects, fields and flows) runs against a Salesforce sandbox org and is available only to users granted developer access.
Role-based access
Access is role-based. Viewers are strictly read-only; only users granted developer access can run the build & deploy pipeline; and any change still passes through an explicit approval step. Not everyone with a login can make changes.
No AI training on your data
Our model provider (Anthropic) is contractually barred from using your data to train models. Only the question text and the relevant metadata excerpt for that question are sent for inference. Zero-Data-Retention is available on request.
Encryption everywhere
TLS 1.2+ in transit end to end. At rest: S3 with SSE-AES256, DynamoDB and EBS encrypted, and secrets in SSM SecureString under a customer-managed KMS key with automatic 365-day rotation.
Private network, zero inbound
AskLumo runs in a private VPC subnet with no public IP and zero inbound security-group rules, so no external entity can initiate a connection. Egress exits a NAT Gateway with a fixed, allowlistable IP.
Security controls
Continuously applied across our AWS infrastructure and processes.
Subprocessors
The third parties that help deliver AskLumo, and what they process. All hosted data stays in AWS us-east-2 (Ohio); other regions on request.
Subprocessor
Role & data shared
Compliance
Amazon Web Services
All hosted infrastructure (EC2, S3, DynamoDB, SSM, CloudWatch, GuardDuty, KMS)
SOC 1/2/3, ISO 27001/27017/27018, PCI DSS, FedRAMP
Anthropic
Model inference; question text + relevant metadata excerpt only
SOC 2 Type II · no training · ZDR on request
Salesforce
Your own tenant, accessed via a customer-owned integration user
Your existing Salesforce posture
Slack
Outbound notifications only; no record data forwarded
Your existing Slack posture
Frequently asked questions
The questions security and procurement teams ask most, answered from our real architecture.
Security package
The posture on this page is public. Detailed materials, including our full Security Overview and architecture & data-flow diagram, are shared with your security team on request under NDA. We respond within one business day.
Security OverviewNDA
Full architecture, data flows and control narrative.
Architecture & data-flow diagramNDA
Network, tenancy and data-flow diagrams in detail.
SIG Lite / CAIQOn request
Completed standardized vendor questionnaire.
DPA & mutual NDAOn request
Data Processing Addendum and MNDA for signature.
Audit-log & Security Hub exportOn request
CloudTrail and AFSBP findings for a chosen window.
Penetration test summaryOn request
Summary of our latest third-party assessment.
Prefer email? Reach our security team directly at security@cloudprism.io.