As an AI agent for LINE marketing, Lumo is designed and operated with the safe handling of your important data as its top priority. It covers infrastructure, data protection, and AI safety — as well as the security features you can use yourself.
How Lumo approaches security
Lumo is built around data protection across the entire service, so businesses can confidently entrust their LINE marketing to it.
- Your data is isolated per contract, so it cannot be viewed from other workspaces
- Data in transit and at rest is encrypted to protect it from being read by third parties
- Any critical operation performed by the AI agent always requires your approval first
Infrastructure
Lumo runs on a highly reliable cloud foundation backed by multiple layers of defense.
| Item | Details |
|---|---|
| Cloud foundation | Operated on a major public cloud |
| Edge defense | Multi-layered defense with CDN, WAF, and DDoS protection |
| Encryption in transit | All communication is encrypted with SSL/TLS |
| Encryption at rest | Stored data is encrypted and protected |
| Backups | Data is backed up automatically |
Data protection
Your data is isolated and managed on a per-workspace basis.
- Data is independent for each workspace and cannot be accessed from other workspaces
- Your data is never used to train external AI models
- Information handled by the AI agent is never shared beyond the boundaries of your workspace
A workspace is identified by its Lumo ID, and Members, LINE Official Accounts, broadcast data, and more are all managed within this unit.
Where data is stored
The database and its backups are stored in Google Cloud's Tokyo region (in Japan). Some data uses locations outside Japan because of the nature of the processing.
| Data | Where it is stored or processed |
|---|---|
| Database (friends, messages, broadcasts, settings, and so on) and backups | Google Cloud Tokyo region (in Japan) |
| Files such as images, videos, audio, and documents received on LINE, and images generated by AI | Cloudflare R2 Asia-Pacific region |
| AI agent processing (text generation, analysis, embeddings) | Google Cloud Tokyo region. Processing is completed within Google Cloud and is not sent to external AI services |
| AI image generation | Google Cloud global locations |
| Text extraction (OCR) of PDFs added to the Knowledge Base | Google Cloud US region |
| Content delivery and tracking links | Cloudflare edge locations (no personal data is stored) |
Encryption and backups
Data at rest is encrypted with AES-256, and data in transit with TLS 1.2 or later.
- Your LINE Official Account's channel access token and channel secret, and your friends' email addresses and phone numbers, are encrypted at the application level in addition to database encryption
- Regular full backups and point-in-time recovery let us restore to any point in time. The recovery time objective is under 1 hour, and the recovery point objective is under 5 minutes
- Core services always run on multiple instances, with a target monthly uptime of 99.9%
Data deletion
Deleting a Workspace and deleting a friend remove different data and follow different flows.
When you delete a Workspace
Access and external integrations stop the moment you request deletion, and the data is physically deleted after a 30-business-day grace period. During the grace period, you can restore the Workspace by contacting support. After physical deletion, support issues a certificate of deletion. Copies remaining in backups are erased within 14 weeks at most. For details, see the deletion section of "Workspace Settings".
When you delete a friend
There are two ways to delete a friend: a regular deletion and "Permanently delete personal data". Both delete the conversation history with that friend, files such as received images and videos, broadcast and tracking records, Workflow execution records, and conversations with the Customer Agent.
"Permanently delete personal data" appears in the menu only after an admin turns it on under Privacy in "Settings" > "Workspace settings" from the navigation menu, and only admins can run it. It is off by default.
"Permanently delete personal data" additionally deletes the following data and prevents the same person from being registered again through a friend add or an import.
- Contact details captured through ID linkage (email address, phone number, name) and the linkage records. If the same person is a friend of another LINE Official Account, the linkage there remains
- The friend's activity history recorded across LINE Official Accounts
Because of how LINE works, Lumo cannot delete the friend relationship on the LINE Official Account side or the chat history in the LINE app. Values written back to Shopify, HubSpot, or Klaviyo must be deleted on each of those services.
Certifications and third-party assessments
The operating company holds the Privacy Mark (certification number 25000199(02)) and operates a personal information protection management system based on JIS Q 15001.
| Item | Details |
|---|---|
| Privacy Mark | Certified (accredited by JIPDEC) |
| LY Corporation certified Technology Partner | Passed the LINE platform's security requirements and technical review |
| HubSpot certified Technology Partner | Complies with HubSpot's security and privacy standards |
| Vulnerability assessments by an external organization | Conducted at least once a year. A summary of the results can be shared after a non-disclosure agreement is signed |
| ISO 27001 and SOC 2 | Not certified |
| Standards and laws followed | Act on the Protection of Personal Information, JIS Q 15001, Telecommunications Business Act, the Ministry of Economy, Trade and Industry's cloud service level checklist, OWASP Top 10 for LLM Applications 2025, and others |
Security features we do not provide
The following features are not provided. If they are a requirement for adoption, consult us through the contact form.
- Single sign-on (SSO via SAML or OIDC). Login supports email address and password, Google accounts, and Apple accounts, and you can add two-factor authentication
- Restrictions on source IP addresses
- User-accessible audit logs of operations. Approval history and records of billing operations are retained
Login has a limit on the number of attempts; after a certain number of failures, the account and the source are temporarily locked.
Subcontractors
Within the scope needed to provide the service, we entrust data handling to the following companies. The full and latest list is in the Privacy Policy.
| Company | Purpose |
|---|---|
| Google Cloud Platform (Google LLC) | Application hosting, database, and AI processing (data is stored in the Tokyo region) |
| Cloudflare, Inc. | Content delivery, edge processing, and file storage |
| LY Corporation | Message delivery (the LINE platform) |
| Stripe, Inc. | Credit card payments (card details are processed directly by Stripe and never pass through Lumo's systems) |
| Raccoon Financial, Inc. | "Paid" bank transfer (invoice payment) service |
| Twilio Inc. (SendGrid) | System email delivery |
| Zendesk, Inc. | Help center and inquiry handling |
Incident response
We monitor service status and security events around the clock.
- When an incident occurs, affected customers receive an initial notification within 72 hours
- We respond in six stages: detection and reporting, initial response, investigation and analysis, recovery, notification, and recurrence prevention
- Service status is published on the status page: https://status.littlehelp.co.jp/
AI safety
The AI agent operates on the premise of safeguards that prevent runaway behavior and mistaken operations. The key point is this: critical operations are always executed only after you approve them.
In Lumo, you handle two things — setting goals and approving — while the agent takes care of planning, preparation, broadcasting, and analysis. For high-impact operations such as executing a broadcast or activating a Workflow, the agent never proceeds on its own and always asks for your approval.
How approval works
Before the agent performs a critical operation, an approval confirmation is shown.
| Item | Details |
|---|---|
| Operations that require approval | High-impact operations such as scheduling or executing a broadcast and activating a Workflow |
| Approval choices | Review the details and choose "Execute" or "Not now" |
| Approval history | You can review your past approval and rejection history afterward |
For more details on how approval works and how to configure your trust settings for the agent, please see the article about approvals.
Security features for you
Lumo provides features to protect your account and workspace.
| Feature | Description |
|---|---|
| Two-factor authentication | Adds an extra verification code at login to protect your account |
| Member permission management | Set each Member as an "Administrator" or "General Member" to control which features they can use |
| API key management | Issue and regenerate API keys for external systems to access Lumo's API |
Two-Factor Authentication
When you enable two-factor authentication, a verification code from your authenticator app is required at login in addition to your password.
- Set it up from "Two-Factor Authentication" in your personal settings
- Scan the QR Code with your authenticator app, enter the displayed 6-digit verification code, and click "Enable"
- For detailed setup instructions, please see the article about two-factor authentication
Member permission management
You can assign each Member the role of either "Administrator" or "General Member".
| Role | What they can do |
|---|---|
| Administrator | Can use all features and also access the admin console menu |
| General Member | Can have usage permissions set individually per feature, such as broadcasts, Chat, and tags |
For more details on permission settings, please see the article about managing Members.
API key management
When integrating Lumo with external systems, you issue and use an API key.
- An API key is shown only once when it is issued, so store it in a secure place
- If an API key is leaked or no longer needed, you can regenerate it to invalidate the previous key
More detailed security information
For more in-depth information such as compliance frameworks, our incident response structure, and availability design, we provide a security white paper.
- Security white paper: https://www.lumo.cx/resources/security
- Security page: https://www.lumo.cx/security
- Responses to security questionnaires and separate agreements: contact form https://www.lumo.cx/contact