Lumivero security and compliance

An independent examination of the design and operating effectiveness of Lumivero’s controls relevant to security, availability, and confidentiality.
A UK government-backed certification, independently verified through hands-on technical testing. Held for the operations that support our Predict! and SharpCloud products.
NVivo Cloud holds certification under the Texas Risk and Authorization Management Program (TX-RAMP). Visit our Trust Center for certification details and the scope of covered services.

Lumivero hosts its cloud services in multiple regions. Available hosting locations and regional options vary by product. Contact us to discuss the hosting options available for your organization.
Customer data in our cloud services is encrypted in transit and at rest. We regularly scan our systems and applications for vulnerabilities and engage independent specialists to perform penetration testing.


Where our products include AI features, neither Lumivero nor its third-party AI providers use your data or inputs to train AI models. You retain ownership of your data, and Lumivero claims no intellectual property rights in your inputs or in the outputs our AI features generate. Lumivero's AI is designed to support your expertise, never to replace it.

Lumivero is committed to handling personal data responsibly and transparently. When we process personal data on your behalf, our Data Protection Addendum sets out our obligations for protecting and handling that data. Our Global Privacy Policy explains how we collect, use, and protect personal data and describes your privacy rights. Our designated Data Protection Officer oversees privacy and data protection matters.

Yes. Lumivero undergoes an annual SOC 2 Type II examination by an independent CPA firm. It covers the controls we use to develop and support both our cloud and desktop software, and to operate our cloud services. You can request the current report through the Trust Center.
Yes. Several of our products support single sign-on and multi-factor authentication. Single sign-on works through industry-standard protocols such as SAML 2.0 and OpenID Connect, which most enterprise identity providers support. Depending on the product, multi-factor authentication is either built in or provided through your identity provider. For details on a specific product, see its documentation or contact us.
Customer data in our cloud services is encrypted in transit and at rest.
We collect information such as your name and contact details you provide to us, and data about how you use our website. Our Global Privacy Policy explains what we collect and why.
No. Under Lumivero's AI Terms of Use, neither Lumivero nor its third-party AI providers use customer data or inputs to train AI models.
Lumivero hosts its cloud services in multiple regions. Available hosting locations and regional options vary by product. Contact us to discuss the hosting options available for your organization. For desktop and customer-hosted deployments, you manage where your project data is stored.
Lumivero uses appropriate safeguards for international transfers of personal data, including Standard Contractual Clauses and the UK Addendum where applicable. Our Data Protection Addendum sets out the relevant protections.
You may have the right to access, correct, or delete your personal data, among other rights. Our Global Privacy Policy explains your rights and how to exercise them.
Yes. We regularly scan our systems and applications for vulnerabilities and engage independent specialists to perform penetration testing.
Lumivero's Data Protection Officer handles privacy and data protection inquiries. Contact details are listed in the Global Privacy Policy.
How can we help you? Contact us.