Security at NeuraLume

Last updated: January 28, 2026

1. Least Privilege Access

We implement strict access controls ensuring users and systems only have access to the minimum resources necessary for their function.

2. Encryption in Transit and at Rest

All data is encrypted using industry-standard protocols both during transmission and when stored in our systems.

3. Internal Access Logging

Comprehensive logging and monitoring of all internal system access to maintain accountability and detect potential security incidents.

4. Customer Data Isolation

Every project belongs to an organisation, and every request is scoped to the organisation the caller belongs to. A project you do not own is not returned to you, and the API does not confirm that it exists.

This isolation is logical, not physical: customers share infrastructure, and separation is enforced in the application and the database rather than by running your data on its own machines. If your procurement requires dedicated infrastructure, tell us and we will say plainly whether we can meet it.

5. No Resale of Customer Content

We do not sell, license, or otherwise commercialize customer-generated content. Your creations remain yours exclusively.

6. Third Parties Who See Your Content

Generating video means sending your brief, prompts and any reference images to the third-party model providers that produce the footage. Their handling of what we send is governed by their terms as well as ours.

We say this plainly because it is the first question a security review should ask, and because no wording on our side changes it. We will name our current providers under NDA, and we will tell you before we add or change one on your account. If a particular provider is unacceptable to you, say so before you start: the pipeline is provider-agnostic, and we would rather answer that up front than discover it at review.

7. Incident Response

If we discover a breach affecting your data, we will tell you what happened, what was affected, and what we are doing about it. We will not wait until we have a complete picture to make the first contact.

We are a small team and we do not staff a 24/7 security desk. Reports sent to the address below are read every business day.

8. What We Do Not Claim

We hold no third-party security certification. We are not SOC 2 audited, not ISO 27001 certified, and not HIPAA compliant. We take no payment details, so we store no card numbers and no government identifiers.

This section exists because the absence of a claim is easy to miss and expensive to assume. If a certification becomes a requirement for you, tell us and we will give you a straight answer about timing rather than a hedge.

Reporting a Security Issue

Found something, or have a question about any of the above? Write to us directly. Reports are read every business day: hello@neuralume.ai