Lunas security

Trust Center

What Lunas holds, who else touches it, the controls that are actually in place, and where our compliance posture genuinely stands.

support@lunas.onePrivacy PolicyLast updated: July 23, 2026

Lunas is a personal health record and medical AI workspace. People upload lab reports, imaging, genetic data, and clinical documents, and talk to Stethos about them. That is among the most sensitive data a person has, and the point of this page is to describe how it is handled without rounding anything up.

Every control listed here is in place today. Where our compliance posture is incomplete, this page says so rather than describing an intention. Claims about security are worth exactly as much as their weakest sentence.

5

Subprocessors

Five external processors receive data, two of which never receive health content. Each one is a link in the chain, so the list is kept deliberately short.

Never

Health data sold or shared for advertising

No advertising SDKs, data brokers, insurers, or employers. No behavioural analytics on health surfaces.

Off by default

Model training on your data

Requires explicit opt-in, de-identification, and human review before any record becomes a training candidate.

Compliance

Where we actually stand

Every framework that applies to Lunas, and our honest status against each. A framework we have not been assessed against is listed as such.

HIPAA

BAAs executed with our AI, storage, and database providers.

Partial — scope-limited

Business Associate Agreements are executed with Google Cloud (AI inference and file storage) and Neon (database). The chain is not complete across every processor, so Lunas does not currently accept protected health information on behalf of a covered entity, and clinician upload of identifiable patient files is not open. Consumer health data that you enter about yourself is not PHI under HIPAA.

FTC Health Breach Notification Rule

We are a vendor of personal health records under the Rule.

In scope

Security incidents affecting health data are evaluated against the Rule's notification requirements, including the 2024 amendment covering unauthorized disclosure and not only intrusion.

Washington My Health My Data

Consumer health data is never sold and never shared without authorization.

In scope

Consumer health data is collected only for the product functions described in our Privacy Policy, is never sold, and is never shared without separate authorization.

SOC 2

No attestation. Controls organized against the criteria, unaudited.

Not certified

Lunas holds no SOC 2 attestation and has not begun an observation window. The controls on this site are organized against the Trust Services Criteria because that is the useful shape for review, not because an auditor has examined them. We will say plainly when that changes.

GDPR

Lunas is not offered to users in the EEA or the UK.

Out of scope

Lunas is not marketed, priced, or offered to users in the European Economic Area or the United Kingdom, and does not target them. If that changes, this page will be updated before it does, not after.

Data

What Lunas holds — and what it never touches

Data we collect

  • Account identity — email address, display name, plan, authentication and security events.
  • Consumer health data — chat conversations, timeline notes, and structured health observations you create or confirm.
  • Uploaded health documents — lab reports, imaging, clinical PDFs, and the text and embeddings extracted from them.
  • Genetic data — genome and pharmacogenomic files, when you choose to upload them.
  • Emergency card data — blood type, allergies, conditions, medications, directives, and emergency contacts, when you create one.
  • Operational metadata — usage counts, rate-limit state, request context on audit records, and error status codes.

Data we do not collect

  • Payment card data — Lunas does not currently process payments, and card data will never touch our systems when it does.
  • Advertising identifiers, third-party tracking pixels, or cross-site profiling of any kind.
  • Precise location, biometric identifiers, or device fingerprinting.
  • Health content in log lines, metric labels, error messages, or URLs — prohibited by policy and enforced in code.

Subprocessors

Everyone who touches your data

View all →
Google CloudAI inference (Vertex AI) and encrypted file storage
NeonManaged Postgres — the application system of record
VercelApplication hosting and serverless compute
ResendTransactional email — sign-in codes and account notices
U.S. National Library of Medicine · openFDAPublic drug and lab reference lookup (RxNav, MedlinePlus)