Skip to content
Luna Health AI logoLuna Health AI

Security

Last updated: July 2026

This page is a drafted template summarizing our security practices. Specific certifications and audit dates should be confirmed and kept current by our security team before publication.

Security is core to how Luna Health AI is built and operated. This page summarizes the technical and organizational measures we use to protect the data clinics and patients trust us with.

Encryption

Data is encrypted in transit using TLS and at rest using industry-standard encryption, covering call recordings, transcripts, and scheduling data.

Infrastructure and Hosting

Luna runs on cloud infrastructure built for security and reliability, with network segmentation and least-privilege access between services.

Access Controls

Internal access to production systems and customer data is limited to personnel who need it, protected with multi-factor authentication, and reviewed on a regular schedule.

Monitoring and Auditing

We monitor our systems for unusual activity and maintain audit logs of access to sensitive data to support incident investigation and compliance reviews.

Independent Audits

Luna Health AI undergoes an independent SOC 2 Type II audit annually to validate the design and operating effectiveness of our security controls.

Incident Response

We maintain an incident response process to investigate, contain, and remediate security events, and to notify affected customers in line with our contractual and legal obligations.

Vulnerability Reporting

If you believe you've found a security vulnerability in our systems, please report it to contact@lunahealthai.ca so our team can investigate promptly.

Employee Security Practices

All personnel complete security and privacy training, and access to customer data is granted on a need-to-know basis and revoked promptly when no longer required.

Contact Our Security Team

For security questions or documentation requests, contact contact@lunahealthai.ca.