Security & Data Handling
Private by architecture. Runs in a private, isolated environment — hosted by Lumynix, or on your own premises if your policies require it.
How it's architected
- Application tier: every request is authenticated and scoped to a single site's data context — no code path can reach another site's records, and isolation is enforced at the data boundary, not just in application logic.
- Data tier: each site has its own database. There are no shared tables across sites — your data is never rows in a shared table.
- AI tier: models run on hardware Lumynix controls. No third-party AI APIs are in the inference path. Your data is never used to train models that serve other customers.
If your security questionnaire asks directly: database-per-site isolation, every request scoped to a single site's data context, AI inference on Lumynix-controlled hardware, no third-party AI APIs.
Deployment tiers
Who it's for
Lumynix Private Cloud
Independent research sites that want zero infrastructure
On-Premises
Networks / institutions with data-residency mandates
Onboarding
Lumynix Private Cloud
Days
On-Premises
Scoped project (setup fee, travel, hardware)
Where data lives
Lumynix Private Cloud
Your own isolated database, hosted by Lumynix
On-Premises
Entirely on your hardware
AI inference
Lumynix Private Cloud
Lumynix-controlled hardware, no third-party AI APIs
On-Premises
Your hardware
Updates & models
Lumynix Private Cloud
Managed by Lumynix
On-Premises
Scheduled releases
Agreements
Lumynix Private Cloud
BAA signed
On-Premises
BAA + deployment agreement
| Aspect | Lumynix Private Cloud (default) | On-Premises (available) |
|---|---|---|
| Who it's for | Independent research sites that want zero infrastructure | Networks / institutions with data-residency mandates |
| Onboarding | Days | Scoped project (setup fee, travel, hardware) |
| Where data lives | Your own isolated database, hosted by Lumynix | Entirely on your hardware |
| AI inference | Lumynix-controlled hardware, no third-party AI APIs | Your hardware |
| Updates & models | Managed by Lumynix | Scheduled releases |
| Agreements | BAA signed | BAA + deployment agreement |
Frequently asked
Where does our data live?
In your own database — one per customer, never shared tables — hosted in Lumynix's private environment, or on your own hardware with an on-premises deployment.
Does AI train on our data?
No. Your data is never used to train models that serve anyone else, and it never touches a third-party AI service.
Who can see our data?
Your staff, and the Lumynix operations necessary to run the service under a signed BAA. No AI vendors, no data brokers, no shared models.
Can we self-host?
Yes — on-premises deployment is available for organizations whose policies require it. Most customers choose Lumynix Private Cloud for zero-infrastructure onboarding.
Are you HIPAA compliant?
The platform is architected for HIPAA environments: database-per-customer isolation, no third-party AI processors, encryption, and audit logging, operated under a Business Associate Agreement. Ask us for the security overview.
Have a security questionnaire or a specific compliance requirement?
Talk to us