Your data is exactly that.
Yours.

We hold the records a business runs on. Our own business depends, every single day, on keeping them safe from attackers, keeping them through a disaster, keeping every version of them, and keeping them private — and on handing them all back the moment you ask.

Safe from attackers

Isolation enforced in the database itself, encryption everywhere, and an independent lab that checked our work.

Safe through a disaster

Continuous backup, copies in a second geographic region, and vaults nobody can empty early.

Versioned and recoverable

Rewind to any five-minute point in the last two weeks. Export the lot whenever you like.

Your data is safe from attackers.

The whole picture — access control, code review, our compliance status, and the certified infrastructure we build on — is on how we protect your data.

Isolation the database enforces, not just the code

Every record carries a tenant id and is gated by PostgreSQL Row-Level Security. Reaching another tenant is not a bug we guard against — it is a query the database refuses.

Encrypted in transit and at rest

TLS 1.2 or higher on every request; AWS KMS encryption underneath. Secrets like OAuth tokens are encrypted again at the application layer.

Checked by someone other than us

An independent lab verified our application-security baseline against OWASP ASVS — all 14 categories passed, under CASA Tier 2.

Your data survives a disaster.

What we can restore, how fast, and what we do if a whole region fails — with the numbers behind each target — is on backup and recovery.

Rewind to any five-minute point in the last two weeks

Beyond that we keep discrete restore points on a rolling schedule: daily for two weeks, weekly for two months, monthly for a year.

Copies in a second geographic region

Weekly and monthly database restore points are copied to a second region, under a separate key.

Vaults that cannot be emptied early

A restore point cannot be removed before its retention expires. Lifting that lock takes a separate, privileged action, and it is logged.

Without asking us

Your data is versioned, and you can take it.

Most of what people write to us for, you can already do yourself — no request, no notice period, no fee.

Download all of it, any time

Any admin can export your workspace's business data, whole or one module at a time, from Admin settings.

See an earlier version of a record

Important records keep their own history: what changed, when, and who changed it.

Undo a deletion

Deleting is usually not erasing — most records are hidden rather than removed. Bulk-deleted deals can be undone on the spot; for anything else, ask us and we will put it back.

And if you leave, take it with you

You export first. Then we delete your workspace and send written confirmation of exactly what was removed. What happens if you leave →

And it stays private.

What we collect, why, and your rights over it are in our Privacy Policy. A customer DPA is available on request from privacy@panluma.ai.

You are the controller; we are the processor

For the personal data your business puts into PanLuma, you decide the purpose and we act on your instructions. We sign a DPA with you, and with every sub-processor.

We publish who else touches it

Every third party that processes customer data, what they do, where, and under which DPA. See the list →

Your AI conversations are not training data

Our LLM provider does not train on API customer data, and tenants can shorten how long AI chat history is kept.

Go deeper

Depending on who is asking

Evaluating PanLuma

Privacy Policy · Terms of Service · Sub-processors · DPA on request

On a security team

How we protect your data · Backup & recovery · CASA Tier 2 certificate · full policy pack on request

A security researcher

Disclosure policy · security.txt · Hall of Fame

 Contact us: Security: security@panluma.ai ·  Privacy / data-subject requests: privacy@panluma.ai ·  General: hello@panluma.ai