Lunas security

Trust Center

What Lunas holds, who else touches it, the controls that are actually in place, and where our compliance posture genuinely stands.

support@lunas.onePrivacy PolicyLast updated: July 23, 2026

Subprocessors

Everyone who touches your data

This list is the complete set of external processors that receive data from Lunas. We publish it because a short chain is a security property, not a limitation. If a processor is added, changed, or removed in a way that affects your data, this page and our Privacy Policy are updated before the change takes effect.

Google Cloud

BAA executed

AI inference (Vertex AI) and encrypted file storage

Receives
Chat text, uploaded file bytes, extracted text, embeddings, stored health documents
Region
United States

Neon

BAA executed · HIPAA enabled

Managed Postgres — the application system of record

Receives
Health observations, timeline notes, chat messages, genetic and pharmacogenomic records, audit trail
Region
United States

Vercel

Scope-limited — no covered-entity PHI

Application hosting and serverless compute

Receives
All application data in transit through request handling
Region
United States

Resend

No health data

Transactional email — sign-in codes and account notices

Receives
Email address and one-time codes only. No health content, ever.
Region
United States

U.S. National Library of Medicine · openFDA

No personal data

Public drug and lab reference lookup (RxNav, MedlinePlus)

Receives
Bare catalogue codes and canonical drug names only — no identifiers, values, or free text
Region
United States