Trust and security
Built to be checked
Luminid asks people to trust it with their work and their data. This page explains how the platform is secured, how scoring stays honest, and exactly who processes data on our behalf. Plain language, and no badges we have not earned.
Security posture
How the platform is secured
The database denies by default
Every table is protected by row level security. Access is denied unless a policy explicitly allows it, so your data is invisible to other users at the database layer, not just hidden by the interface.
Sign in uses PKCE
Authentication runs on the PKCE flow, the current standard for browser sign in. Sessions are issued and rotated by our authentication provider. There is no homegrown cryptography anywhere in the product.
Encrypted in transit and at rest
All traffic between you and Luminid runs over HTTPS. Stored data is encrypted at rest by the platforms that hold it. There is no unencrypted path to your data.
Privileged keys never leave the server
The credentials that can bypass database policies exist only in server code. They are never sent to the browser, never included in client bundles, and never exposed through the interface.
The infrastructure underneath
Certified platforms, honest claims
Luminid runs on Supabase for the database, authentication, and storage, and on Vercel for hosting and delivery. Both companies publish SOC 2 Type 2 attestations for their platforms, which you can read on their own security pages.
Luminid itself does not hold a SOC 2 certification today. We would rather say that plainly than imply otherwise with borrowed badges. When that changes, this page will say so.
Simulation integrity
Why a verification is hard to fake
A verification is only worth something if it is hard to fake, so the simulation itself is protected. The environment can detect and block automated browsers before a session starts. Signals from within a session are reviewed by people, and no one is ever penalized by an automated signal alone. Voice formats exist because a live spoken answer is far harder to fake than a typed one, which is why every verification states the format it was demonstrated in. We keep further operational detail private, because a precise map of the defenses would mostly help the people trying to get around them.
AI transparency
Automated scoring, disclosed every time
Simulation responses are scored by an automated system against documented criteria that our team wrote and reviewed. You are told this before it happens, every scored result quotes your own work as its evidence, and you can request a human review of any result. Automated scores never make hiring decisions on their own. The full methodology is public, from the scoring formula to the fixed threshold.
Subprocessors
Who processes data so Luminid can run
These are the services that process data on our behalf. This is the complete list, and it matches the one in the privacy policy.
| Service | What it processes |
|---|---|
| Supabase | Database, authentication, and file storage. |
| Vercel | Application hosting and content delivery. |
| Anthropic | Automated scoring of simulation responses against documented criteria. |
| OpenAI | Voice transcription and the spoken counterpart in voice simulations. |
| Resend | Transactional email delivery. |
| ONVO Pay | Payment processing for employer subscriptions. Job seekers never pay. |
| Google and LinkedIn | Optional sign in. Used only if you choose to sign in with one of these accounts. |
Responsible disclosure
Found a security issue?
Write to security@luminid.org and we respond within 72 hours. Tell us what you found and how to reproduce it, and give us a reasonable window to fix it before any public disclosure. We will not take legal action against good faith security research.
security@luminid.orgYour data
Your data stays yours
You can export your data and schedule account deletion from your settings at any time. Deletion removes your profile and your verified results. For anything else about your data, write to hello@luminid.org and a person will answer. The full detail lives in the privacy policy.
Read the privacy policy