This page gives an overview of security procedures that we follow building the Luma company and product.
We process payments with Stripe, which is a fully PCI-compliant service provider. They are certified with PCI DSS v3.2.1 compliance.
Luma does not process or store any payment information.
Luma does not share or sell any of your data with other sources. You can read more information about how seriously we take your privacy at events/privacy.
We use Amazon AWS ECS + EC2 to host our technical infrastructure and servers. Amazon AWS has the following compliance: PCI-DSS Level 1 Service Provider, ISO 27001 certified, and SAS-70 Type II and SSAE16.
We employ both internal and external testing and validation of our development process.
Our application and code are scanned for static and dynamic code vulnerabilities. All engineers receive security training.