Security & trust

Built for healthcare data, from the ground up.

UK-hosted, aligned with UK GDPR and the DPA, with passwordless sign-in, logically separated tenants and fine-grained access control. The platform is secure by design, not by bolt-on.

How we protect your data

Healthcare-grade by default.

UK data residency

All data encrypted in transit and at rest, hosted in UK data centres.

Passwordless sign-in

Every sign-in needs a one-time code to a verified email or mobile, so access depends on a verified channel, not a stored password. Passkeys and authenticator-app MFA are supported, and you can require them for your staff.

Per-practice isolation

Every organisation's data is logically separated, with strict tenant-scoped access controls; Enterprise can request dedicated infrastructure.

GDPR & DPA

Compliant by design, with a documented sub-processor chain.

Safe migration

Assessment first: we analyse your data and agree a written plan, with a parallel-run before go-live.

Full export, on request

Your data is yours: we provide a full export whenever you ask, on every plan.

Compliant by design
GDPR & UK DPA NHS DSP Toolkit: Standards MetCyber Essentials Certified
Security contact

Security questions?

If you have questions about our security practices, or need more detail for your due diligence process, we are here to help.

Report a security concern or request information

security@luminadental.co.uk
Acknowledged within 24 hours Responsible disclosure welcome

We can complete security questionnaires, provide additional documentation, or arrange a call with our technical team for enterprise practices.

Security you can hand to your DPO.

Read our security practices or talk to our team about Enterprise controls.

Preferences saved.