LumiWed Trust Center

LumiWed Trust Center

Security and privacy, built into every wedding site.

Everything you need to evaluate LumiWed as a vendor: how we handle your data, who we share it with, and where it's processed.

Where things stand today

LumiWed is an early-stage company. We don't yet hold independent certifications like SOC 2 or ISO 27001 ourselves — here's what we do have in place.

  • Multi-tenant isolation

    Every table in our database carries a wedding ID, enforced by Postgres Row Level Security. One couple’s data is never reachable from another’s session.

  • Encryption in transit

    All traffic to LumiWed properties runs over TLS through Cloudflare’s edge network.

  • Payments never touch our servers

    Stripe handles card data end-to-end. LumiWed never stores payment card numbers.

  • Built on audited providers

    Supabase, Clerk, Stripe, and Cloudflare each maintain their own independent compliance certifications — see their own trust pages for specifics.

  • Guest access without passwords

    Guests reach a wedding site through an unguessable, revocable magic-link token — never a shared password.

  • Scoped internal access

    Internal admin tooling runs on its own authentication, separate from couple accounts, so support access is auditable and least-privilege.

Subprocessors

15 third parties process personal data on our behalf. The full list, with what each one does and where, is public.

View the subprocessor list

Compliance roadmap

We plan to pursue formal certifications like SOC 2 as LumiWed grows. If you need a specific attestation or answers to a security questionnaire today, get in touch — we're happy to work through it directly.

Questions?

For security, privacy, or compliance questions, get in touch.