Security

Your compliance data, treated like compliance data.

Luxima holds the product data behind your EU compliance — so protecting it is part of the product, not an afterthought. Here's how we keep it safe, and where it lives.

EU servers only

Your data is stored and processed exclusively on servers in the European Union — our primary region is AWS Dublin. It is never transferred outside the EU, full stop.

Secure AWS infrastructure

Luxima runs on Amazon Web Services, inheriting the physical, network and platform security that protects some of the world's most demanding workloads.

Standards-led

We build to recognised standards: GDPR by design, security practices aligned with ISO/IEC 27001 principles, and OWASP guidance in how we write and review code.

How we work

The controls that protect your data day to day, across the whole platform.

Encryption everywhere

All data is encrypted in transit with TLS and at rest with AES-256. There is no unencrypted path through the platform.

Strict access control

Least-privilege access, multi-factor authentication and role-based permissions — for our team as well as yours. Nobody sees data they don't need.

Isolated environments

Production is fully separated from development and testing, and customer data never leaves the production environment.

Backups and continuity

Automated, encrypted backups — stored within the EU like everything else — with restores we actually test, not just configure.

Monitoring and audit trails

Continuous logging and alerting across the platform, so unusual activity is spotted early and every change to your data is traceable.

Secure development

Code review on every change, dependency and vulnerability scanning in our pipeline, and OWASP secure-coding practices as the baseline.

Your data stays in the EU.

Every byte of customer data Luxima holds — product data, passports, documents, backups — is stored and processed on servers physically located in the European Union, with AWS Dublin as our primary region. We do not replicate, process or transfer your data outside the EU, so you never have to reason about international transfer mechanisms on our account.

We operate under GDPR as both a legal obligation and a design principle: data minimisation, purpose limitation and clear retention rules are built into the platform. A data processing agreement is available to every customer — see our privacy policy for the details.

Standards are our product. We exist to help businesses meet EU regulation, so we hold ourselves to the same discipline: security practices aligned with ISO/IEC 27001 principles, OWASP guidance in development, and the emerging EU Digital Product Passport technical specifications in what we build.

Found a vulnerability?

We welcome reports from security researchers. If you believe you've found a vulnerability in Luxima, email info@mbpsystems.com with the details and we'll respond quickly. Please give us reasonable time to fix an issue before disclosing it publicly — we'll keep you informed throughout.

Questions about security?

We're happy to walk your team through our architecture, controls and data handling in detail.