Security & compliance

Security that earns a clinic's trust.

Health information stays in Australia, is encrypted when stored and sent, and is available only to people whose role requires it.

Australian data residency Encrypted in transit & at rest Stronger staff sign-in Working towards recognised standards

How we protect it

The protections healthcare should expect.

Australian residency, encryption, controlled access and recoverability are treated as foundations—not extras.

Australian data residency

Patient and clinic data is kept in Australia, in the Sydney region. Details submitted through this website are stored in Australia too.

Encrypted in transit and at rest

Information is encrypted while it is sent and while it is stored in databases, files and backups. Sensitive system credentials are kept separately from the applications people use.

Mandatory staff MFA

Every staff member uses an authenticator code as well as a password. Extra identity checks protect sensitive account and security changes. Clinics can require the same added protection for patients.

Access limited by role

Role-based permissions limit each person to the information their work requires. Practice data is separated, and sensitive access is protected and auditable.

Daily backups

Clinic data is backed up every day and kept separately from day-to-day use, so it can be recovered if something goes wrong.

Several layers of protection

Public forms are protected from automated abuse, the website uses modern browser safeguards, and security researchers have a clear way to contact us.

Patients stay in control of sharing

In myLumii, each clinic is separate. People choose which kinds of health information to share and can change their mind later. Journal, food and personal exercise areas remain private.

Security FAQ

Where is our data stored?

In Australia, in the Sydney region. That includes patient and clinic information as well as details submitted through this website.

Is Lumii ISO 27001 certified?

Lumii is not currently ISO 27001 certified. We are building our security management practices towards that standard, with access control, encryption, logging, backups and incident response already part of how Lumii is designed and operated.

How do you handle the Australian Privacy Principles?

Australian data residency, role-based access, audit logs and a documented incident-response plan support our alignment with the Australian Privacy Principles. Our privacy policy explains what we collect, how we use it and when it may be disclosed.

How do I report a vulnerability?

Email security@lumii.com.au or see our security.txt. We welcome responsible disclosure.

Can every connected clinic see everything in myLumii?

No. Each clinic connection is kept separate, and supported health information is shared by category only when the individual chooses. Personal journal, food and exercise spaces do not include clinic sharing by design.

Found a security issue? Email security@lumii.com.au or see our security.txt. Read our privacy policy for how we handle data.

Security questions welcome

Trust should start before you sign up.

Talk to us about your practice's privacy, security and governance requirements. We'll answer plainly and share the detail your team needs.

Register interest We’ll reply personally.