Security & trust

What we do, what we do not do, and how you can check

Most of a PDF vendor's security questionnaire is about what happens to your documents on their servers. Your documents never reach a server here: the engine runs inside your process and makes no network request. That answers a large part of the questionnaire before it starts, and the rest of this page answers the remainder.

Data flow

Where your data goes, stated as three separate systems, because they are three separate systems.

The engine, in your process
No network at all

Documents are opened, composed, rendered and written entirely inside your own process. The engine opens no socket, resolves no hostname and reports no usage. There is no telemetry to disable because there is none to send.

Licence verification is part of that: the key is checked locally. There is no activation call and no licence server.

This website
Account and order data

What you type here: your account, your organisation, orders, invoices, licence records, support tickets and anything you attach to one. Kept for as long as the commercial relationship and the relevant accounting law require it.

You can export or close your account from the portal without asking us.

Payment
Never on our servers

Card details are entered on the payment provider's hosted page. No card number, expiry or security code reaches this platform, which is what keeps the assessment at SAQ-A rather than making us a cardholder-data environment.

Bank transfer and purchase order involve no card at all.

Certifications we do not hold

Listed explicitly. A vendor that is silent about certification is a vendor you have to ask, and the answer you get in a sales call is worth less than the one printed here.

Standard Our position
ISO/IEC 27001 Not certified. No audit has been performed and none is claimed.
SOC 2 Not certified. No report exists.
PCI DSS Out of scope by design. Card details are entered on the payment provider’s hosted page and never reach this platform, which is what keeps the assessment at SAQ-A.
Penetration test No third-party test report is published. The platform is verified by its own automated build, which is a different and weaker thing, and is described as such.

Reporting a vulnerability

Open a support ticket marked security, or reply to any address you already have for us. We will confirm receipt, tell you whether it is reproducible, and name the release that carries the fix. If it affects the engine rather than this site, the fix ships as a build and your key covers it under the ordinary maintenance rule.

We do not run a bounty programme and we do not pretend to. What we do is answer.

Who you would be buying from

Lumas Softech
705, Alif Apartment
Sarkhej-Makraba Road, Sarkhej
Ahmedabad 382210, Gujarat
India
support@lumaspdf.com · Contact page

The tax identifier and register number are still being registered, so invoices issued today say on their face that they are not yet tax documents.

Availability and recovery

The engine keeps working whatever happens to us: your key is verified locally and the binaries you have are yours. What depends on this platform is new downloads, new keys and support.

Backups are taken, hashed, registered and restored into a throwaway database to prove they replay. A backup that has never been restored is not counted here as a backup.

Send us the questionnaire

If your review needs answers in your own template rather than ours, send it with a quote request and it comes back filled in.