Lumee™ · Security

Your data stays yours. Here is exactly how.

How we keep your business data isolated, private, and under your control.

For customers & security reviewers · July 2026 · v1.0

Lumee™ is the intelligence layer of Ember Illuminate™: it lets your team ask questions of your own business data, in plain language, from the AI assistant you already use. This page explains the security model in plain terms, and everything on it describes what is built and running today, not a future promise.

The short version

Your data never leaves your Google Cloud project. Lumee™ queries it in place and never copies or warehouses it. Conversations run through your own AI provider seat under your agreement, not ours. Every customer gets a fully separate, read-only deployment.

01 · Architecture

Architecture & tenant isolation

Each customer is served by a dedicated deployment pinned to that customer alone. There is no shared multi-tenant data path. Isolation is enforced in layers.

Project boundary

Your data lives in its own Google Cloud project.

Service account

The runtime identity holds read-only access to your approved datasets only. No shared cross-customer service account exists.

Query gateway

Every query is dry-run first, and every table it references is checked against your approved list, including joins. Anything else is refused.

Read-only, capped

Only single-statement SELECT queries are accepted, with per-query data-scan limits and billing caps.

These controls are covered by automated tests and adversarial evaluation cases: cross-tenant probes, prompt-injection attempts, off-limits queries, run against the live gateway before every deployment. A build that fails certification does not ship.

02 · Access

Identity & access control

  • Your identity provider. Users sign in with Google OAuth using their own workplace account. Lumee™ requests the minimum possible scope, email identity only.
  • You control the door. Access is authorized by your workspace domain and/or a Google Group your team manages. Remove someone from the group and their access is gone.
  • Fail closed. If an authorization check errors, access is denied, never assumed.
  • Tokens encrypted at rest. OAuth tokens are stored encrypted, with expiry enforced.
03 · Models

Your AI, your agreement

Lumee™ is the gateway, not the model. Prompts and responses flow through your own AI provider seat (Claude, ChatGPT) under your existing agreement with that provider. Each Ember never processes your conversations through its own model account.

04 · Data handling

Data handling & privacy

  • No query results are logged. The audit log records who asked, which datasets, when, and how much data was scanned, never the rows that came back.
  • Encryption everywhere. TLS in transit, encryption at rest on all Google Cloud storage.
  • No long-lived credentials. The platform uses zero service-account keys. All workloads authenticate through Google Cloud's native keyless identity. Application secrets live in Google Secret Manager, never in code.
  • Synthetic data only outside production. Development, testing, and our public demo run on fully invented datasets. Your data is never used for development or demonstrations.
05 · Subprocessors

Subprocessors

Google Cloud Platform

Hosting, BigQuery, identity, secret storage, logging.

Anthropic

Pre-deployment evaluation harness only (certification testing).

Your AI provider is your vendor under your own agreement, not our subprocessor for your conversations.

06 · Roadmap

Security roadmap

We are deliberately building toward SOC 2 from day one: controls and evidence trail first, formal audit when a customer engagement calls for it. In progress: organization-wide data-access audit logging and policy constraints, infrastructure-as-code tenant provisioning, expanded IAM-layer isolation testing, and a formal written policy set.

Questions?

We'll walk your security team through it.

Happy to review the architecture line by line, complete questionnaires, or provide additional detail. Contact info@eachember.com.