Lux runs on infrastructure you own — not a multi-tenant SaaS that holds your accounts hostage. Here's exactly how your credentials, your data, and your money are protected. Every control below is enforced in the product, not a promise.
Every platform password and API token you connect is sealed in a Fernet (AES-128) encrypted vault. It is never written to a profile, a log, or any plaintext file — only the running server can decrypt it to do the work.
Lux refuses to accept or store raw card numbers, CVV, or card data — intake actively rejects card-number-shaped fields. Billing runs through a separate, dedicated payments flow. PCI surface stays off our box entirely.
Your accounts, your data, and your full history live on owned hardware — not rented SaaS that disappears when you stop paying. Documented, portable, and yours to take with you. No lock-in.
Access is governed by role-based capabilities enforced on the server for every request — a client only ever sees their own data, and one client's account can never read another's. Isolation is checked, not assumed.
Onboarding and share links are single-purpose, time-limited, and bound to one client — they can't be replayed as a login or used to reach another account. OAuth connections are signed and verified end to end.
Your data is snapshotted nightly to encrypted off-box storage, with restores verified — so a hardware failure or mistake is recoverable, and the backup itself is unreadable without the key.
The bright lines — non-negotiable, built into how the system works.
Bring them to the demo — we'll walk your exact deployment, where your data lives, and who can see what.
Book a call →