Common questions about keeping your Lumo account secure — covering login, two-factor authentication, and passwords — are answered below.
How do I set up two-factor authentication?
You can enable two-factor authentication from the two-factor authentication section of your personal settings screen. It adds an identity check at login by using a 6-digit code generated by an authentication app.
To set it up, you need a TOTP-compatible authentication app (a smartphone app) such as Google Authenticator.
Setup steps
| Step | Action |
|---|---|
| 1 | Open your personal settings screen and check "Enable" in the two-factor authentication section |
| 2 | Scan the displayed QR Code with your authentication app (if you can't read the QR Code, use the manual entry code shown on the screen) |
| 3 | Enter the 6-digit code from your authenticator app into "Verification Code" |
| 4 | Click "Enable" |
Once activation is complete, you will be asked to enter a 6-digit verification code at each subsequent login.
What should I do if the verification code is not generated correctly?
If your authentication app's time synchronization is off, the generated code may not match and you may be unable to log in. First, check your time settings.
Points to check
- Check the time synchronization setting of your authentication app
- Set your smartphone's time setting to "Automatic"
- If reviewing the time settings doesn't resolve the issue, please contact Lumo support
What should I do if I can no longer access my authentication app?
If you can no longer open your authentication app because you lost your smartphone or changed devices, please contact Lumo support.
After verifying your identity, we will reset two-factor authentication for you. Once it is reset, please set it up again with a new authentication app.
How do I disable two-factor authentication?
You can disable two-factor authentication from the two-factor authentication section of your personal settings screen. Disabling it also requires identity verification.
In the two-factor authentication section, select "Disable" and enter the 6-digit code shown in your authentication app.
What should I do if I forget my password?
You can reset your password from the login screen. A reset link will be sent to your registered email address.
Reset steps
| Step | Action |
|---|---|
| 1 | Click "Forgot your password?" on the login screen |
| 2 | Enter your registered email address and send the reset link |
| 3 | Set a new password from the link in the email you receive |
The reset link has an expiration date. If it expires, repeat the same steps to reset your password again.
If the email doesn't arrive
- Check your spam folder
- Confirm that the email address you entered matches your registered one
- If it still doesn't arrive, please contact Lumo support
Are there any requirements for the characters I can use in my password?
To keep your account secure, your password must meet a few requirements. When you set a new password, be sure to satisfy all of them.
| Requirement | Details |
|---|---|
| Length | At least 8 characters |
| Letters | Includes at least one letter |
| Numbers | Includes at least one number |
| Repetition | Do not use the same character three or more times in a row |
If a requirement is not met, an error will be shown on the settings screen. Follow the displayed message to make corrections.
Are you certified for ISO 27001 or SOC 2?
No, we are not.
The operating company holds the Privacy Mark (JIS Q 15001) and has vulnerability assessments conducted by an external organization at least once a year. As a certified Technology Partner of LY Corporation and HubSpot, we meet the security requirements of each. For responses to security questionnaires, consult us through the contact form: https://www.lumo.cx/contact
Can I use single sign-on (SSO)?
No.
Login supports email address and password, Google accounts, and Apple accounts. To protect your account, enable two-factor authentication.
Can I restrict access by source IP address?
No.
Login has a limit on the number of attempts; after a certain number of failures, the account and the source are temporarily locked. Manage access by combining Member permission management with two-factor authentication.
Can I view an audit log of operations?
We do not provide an operation log that users can view.
The history of approvals and rejections for the AI agent is available on the management screen. Records of billing operations and deletions are retained on Lumo's side.
Where is my data stored?
The database and backups are stored in Google Cloud's Tokyo region (in Japan).
Files such as images and videos received on LINE are stored in Cloudflare R2's Asia-Pacific region, and text extraction (OCR) of Knowledge Base PDFs is processed in Google Cloud's US region. For details, see the section on where data is stored in "About Lumo's Security".
Can we sign a data processing agreement (DPA)?
For separate agreements and non-disclosure agreements, consult us through the contact form.
The personal information we handle on your behalf is governed by the published Personal Information Processing Agreement. For where to find the documents, see "Where to find contract, privacy, and security documents".
Can I get a certificate that my data has been deleted?
Yes.
When you delete a Workspace, support issues a certificate of deletion after the data is physically deleted following the 30-business-day grace period.
Can I get the security white paper or vulnerability assessment results?
You can download the security white paper from the website: https://www.lumo.cx/resources/security
A summary of vulnerability assessment results is shared after a non-disclosure agreement is signed. Consult us through the contact form.