LumiWed Trust Center
Security and privacy, built into every wedding site.
Everything you need to evaluate LumiWed as a vendor: how we handle your data, who we share it with, and where it's processed.
Where things stand today
LumiWed is an early-stage company. We don't yet hold independent certifications like SOC 2 or ISO 27001 ourselves — here's what we do have in place.
Multi-tenant isolation
Every table in our database carries a wedding ID, enforced by Postgres Row Level Security. One couple’s data is never reachable from another’s session.
Encryption in transit
All traffic to LumiWed properties runs over TLS through Cloudflare’s edge network.
Payments never touch our servers
Stripe handles card data end-to-end. LumiWed never stores payment card numbers.
Built on audited providers
Supabase, Clerk, Stripe, and Cloudflare each maintain their own independent compliance certifications — see their own trust pages for specifics.
Guest access without passwords
Guests reach a wedding site through an unguessable, revocable magic-link token — never a shared password.
Scoped internal access
Internal admin tooling runs on its own authentication, separate from couple accounts, so support access is auditable and least-privilege.
Subprocessors
15 third parties process personal data on our behalf. The full list, with what each one does and where, is public.
View the subprocessor listCompliance roadmap
We plan to pursue formal certifications like SOC 2 as LumiWed grows. If you need a specific attestation or answers to a security questionnaire today, get in touch — we're happy to work through it directly.