← Back to home

Security Policy

Last updated: July 11, 2026

Lumus is a product of Digitaro Private Limited, a company incorporated in Singapore.

This Security Policy describes the administrative, technical, and organizational measures Digitaro Private Limited ("Digitaro") applies to protect Lumus and Customer data. Lumus is a product of Digitaro Private Limited, Singapore. Questions: labs@digitaro.co.

1. Security program

We maintain a security program appropriate to the nature of an education SaaS platform, covering access control, encryption, network security, application security, vendor management, monitoring, and incident response. Controls are reviewed as the product and threat landscape evolve.

2. Data protection measures

  • Encryption in transit: TLS for web and API traffic
  • Encryption at rest: storage encryption via cloud provider capabilities for primary databases and object storage where configured
  • Secrets management: API keys, OAuth client secrets, and webhook secrets stored with restricted access; not committed to source control
  • Tenant isolation: Customer data is logically separated in multi-tenant deployments; dedicated deployments available under enterprise arrangements

3. Access control

  • Role-based access within Lumus (e.g., admin, teacher, student, parent)
  • Authentication required for application access; session controls for signed-in users
  • Digitaro staff access to production systems is limited to personnel with a business need, using unique credentials and least-privilege principles
  • Customer administrators control user provisioning and role assignment for their tenant

4. Application and infrastructure security

  • Secure development practices, including code review for material changes
  • Dependency and package management with attention to known vulnerabilities
  • Parameterized database access and input validation at trust boundaries
  • Cloud hosting with network firewalling, hardened defaults, and regular patching
  • Backups of critical data with restoration procedures for disaster recovery scenarios

5. Integrations (including Zoom)

When Customers enable Zoom or other integrations, Digitaro stores OAuth tokens and configuration secrets needed to operate the integration. Tokens are transmitted only over encrypted channels and used solely to perform authorized API calls (e.g., create meetings, sync attendance, import recordings). Customers should:

  • Grant only required Zoom scopes
  • Protect Zoom Client ID/Secret and webhook secret tokens
  • Disconnect Zoom accounts and revoke app authorization when no longer needed

See Zoom documentation for setup and removal steps.

6. Logging and monitoring

We collect operational logs and error telemetry to maintain reliability and investigate security events. Logs may include IP addresses, user identifiers, and request metadata. Access to production logs is restricted.

7. Vendor and subprocessor security

We use infrastructure and SaaS vendors (hosting, storage, email, monitoring, payments) under contractual terms that require appropriate security and confidentiality. We evaluate material vendors for security posture before onboarding where practicable.

8. Incident response

Digitaro maintains an incident response process to detect, contain, investigate, and remediate security incidents. Where a personal data breach affecting Customer data occurs and notification is required by law or contract, we will notify affected Customers without undue delay and provide information reasonably available about the nature of the incident and mitigation steps.

To report a suspected vulnerability or security incident: labs@digitaro.co (subject: "Security Report").

9. Customer responsibilities

  • Configure strong passwords / SSO and manage user lifecycle (joiners/leavers)
  • Assign least-privilege roles within Lumus
  • Secure endpoints used to access Lumus
  • Configure third-party integrations according to vendor and institutional policy
  • Promptly notify us of suspected unauthorized access to your tenant

10. Related policies

Privacy Policy · Data Retention & Protection · Terms of Use

11. Contact

Digitaro Private Limited (Singapore) — Lumus
labs@digitaro.co