ARIAby LuminOne

Trust & Security

Security at ARIA, stated plainly.

ARIA ingests account, sponsor, and market data to do its work. This page is an honest account of how we handle that data at our current stage, including what we have not yet certified.

In short

We do not train or fine tune our models on your data. Your data stays in your own country. ARIA reads only what you grant it, and a person approves every action before anything goes out.

Posture

Where we actually are

SOC 2 status

ARIA is a pre-revenue product. We have not completed a SOC 2 Type I or Type II audit, and we do not claim certification. A SOC 2 readiness program is in progress and we will publish the report and date here once an independent auditor has issued it. If you need the current readiness detail for a security review, email us and we will share where we are honestly.

What this page is

A plain statement of how we handle data and security at our current stage, not a marketing claim. Where a control is not yet in place, we say so rather than imply it. We would rather under-claim than overstate controls we have not yet proven.

Data handling

Your data

What we ingest

ARIA reads the account, sponsor, and market data you scope to us. That can include CRM account records, contact and activity notes, and public market signals you ask us to monitor. We ingest only the systems and scopes you approve.

Model training and fine tuning

We do not train or fine tune our models on your data. If you ask for a customer specific fine tuned model, we build it using only your data, and it is used only for you. Each customer's data is firewalled so no one else can see it. We do not sell customer data and we do not use customer data to train third-party foundation models. The public demo on this site is separate and is not covered by the above: it sends the company URL you enter, and publicly available text about that company, to our search and model providers. It carries no customer data.

Where your data is stored

Your data is stored in your own country. We currently work with customers in the United States, so today that means data stays in the United States. Inputs, along with ARIA's generated drafts and reasoning, are held with our hosting provider.

Deletion and retention

You can ask us to delete your data at any time and we will confirm in writing once it is removed from our systems. At the end of an engagement we delete or return data according to the agreement. Operational logs are retained for up to 12 months.

Controls

Access, approval, and sub-processors

Access controls

Access to customer data is limited to the LuminOne personnel who need it to run your engagement. Access is over authenticated, encrypted connections, and we use the access scopes you grant rather than broad credentials.

Human-approval gating

ARIA does not act autonomously on your systems. Every outward action and every writeback is gated behind a person's explicit approval, and each approved action is logged and reversible.

Encryption

Data is encrypted in transit (TLS). At-rest encryption is provided by our hosting and storage providers (Vercel and Vercel Postgres).

Sub-processors

ARIA relies on third-party sub-processors for hosting, model inference, and operational tooling. A current sub-processor list, naming each provider and its role, is available on request under NDA.

Responsible disclosure

Found something? Tell us.

If you believe you have found a security vulnerability in ARIA, please report it to us before disclosing it publicly. We will acknowledge your report, investigate, and keep you updated. We will not pursue legal action against good-faith research that respects user privacy and avoids data destruction.

Email [email protected] with the subject “Security disclosure”.

Last updated June 25, 2026.