generated: '2026-07-20' method: searched source: https://lumigo.io/security/ standards: - id: soc2-type2 conforms: true evidence: SOC 2 Type II audit performed by Ernst & Young, LLP (EY). - id: hipaa conforms: true evidence: HIPAA compliant; handles PHI securely; ISO 27799 referenced. - id: iso-27799 conforms: true evidence: ISO 27799 (health informatics security) referenced with HIPAA compliance. - id: gdpr conforms: true evidence: Full GDPR compliance stated; DPA available on request. - id: tls conforms: true evidence: Data transmitted over HTTPS (TLS 1.2+); live probe observed TLS 1.3 on lumigo.io. - id: opentelemetry conforms: true evidence: First-party OpenTelemetry distributions (Node/Python/Java/Go) and OTLP ingestion endpoint. - id: oauth2 conforms: false evidence: API access uses static API tokens (x-api-key), not OAuth 2.0. - id: rfc9457-problem-details conforms: false evidence: No public OpenAPI/spec located to confirm problem+json error envelope.