Passer au contenu principal

Centre de confiance

Confiance et sécurité

Ce document est fourni en anglais seulement. Le texte anglais fait foi ; une traduction n’est pas offerte pour le moment.

Cette page explique comment Lumtry protège vos données, où se situe l’IA dans une décision de remboursement, quels sous-traitants nous utilisons et comment l’information circule dans le Service.

Sur cette page

Sécurité

Chaque espace de travail fonctionne selon la même posture de sécurité. Voici ce qui protège vos données aujourd’hui.

  • Isolation des locataires. Les données de chaque organisation sont séparées par la sécurité au niveau des lignes, et le backend revalide l’accès à chaque requête. Un espace de travail ne peut pas lire les dossiers d’un autre espace de travail.
  • Piste d’audit en ajout seul. Chaque décision, signal et dérogation est inscrit dans une piste d’audit qui ne peut être ni modifiée ni supprimée. Chaque entrée porte un ID de corrélation, ce qui permet de retracer un dossier du début à la fin.
  • Aucune donnée de carte brute. Lumtry ne conserve jamais les numéros de carte. Les remboursements et les frais font plutôt référence à un jeton du processeur de paiement, de sorte que les données de carte restent chez le processeur de paiement.
  • Chiffré en transit. Le trafic vers Lumtry est chiffré en transit, et le tableau de bord envoie des en-têtes de sécurité stricts, y compris une politique de sécurité du contenu et l’en-tête HSTS.
  • Notifications automatiques vérifiées. Chaque notification automatique entrante, qu’elle provienne de votre boutique, de votre processeur de paiement ou de Slack, voit sa signature vérifiée avant que Lumtry n’inscrive quoi que ce soit dans vos données. Une notification dont la signature est invalide est rejetée.

Comment Lumtry utilise l’IA

  • Une politique déterministe que votre organisation rédige et versionne décide de chaque dossier. Un remboursement déjà en cours demeure associé à la version de politique sous laquelle il a commencé.
  • Le raisonnement de l’IA est une donnée d’entrée pour cette politique, jamais la décision elle-même. Il évalue les dossiers ambigus et rédige une justification, dans les limites de ce que la politique permet déjà.
  • Une personne approuve tout dossier que la politique ne règle pas d’elle-même, à partir du tableau de bord ou de Slack, avant toute exécution.
  • Le texte destiné aux acheteurs que l’IA aide à rédiger est marqué comme généré par l’IA dès sa conception, sauf si une personne le modifie et l’envoie en son propre nom, afin que vous puissiez distinguer les mots venant d’une personne de ceux venant du modèle.
  • Les acheteurs peuvent demander la révision humaine de leur dossier à partir de la page d’état du retour. Un dossier contesté affiche l’un de trois états : en attente de révision, révisé et maintenu, ou révisé et modifié.

Lumtry ne publie aucun taux de précision ni indicateur de performance pour les décisions assistées par l’IA, car c’est la politique, et non le modèle, qui décide.

Consultez nos sous-traitantsDécouvrez comment les données circulent dans le Service

Sous-traitants

Lumtry travaille avec les fournisseurs ci-dessous pour exploiter certaines parties du Service. Chaque entrée indique son rôle, son statut et ce que nous pouvons confirmer aujourd’hui.

Anthropic

Actif
Détails pour Anthropic
ChampValeurSource
Purpose

Model inference for agent runs on every route class (screen, classify, author, critic, reason, judge) where the tenant's routing policy selects an Anthropic model; the batch lane (judge only) and prompt caching are enabled for this endpoint.

code
Region of processing

Anthropic direct API, US processing. No EU-resident door exists at launch (owner decision 2026-09-12, epic #597: first markets are US and Canada).

code + decision
Data categories

Redacted case text (refund reasons, portal notes, shopper communications), merchant policy text, evidence-pack sections, case timelines, aggregated abuse-risk and sentiment signals, offer parameters, agent outputs under review. Never: processor tokens, card data, full email local-parts, API keys, request headers.

code
Retention on the provider side
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Zero-data-retention / training opt-out

Repo record (memo §8): no-training default for API traffic; Zero Data Retention available on request.

En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

owner
Contractual basis
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Date last verified
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification

OpenAI

Actif
Détails pour OpenAI
ChampValeurSource
Purpose

Model inference for agent runs on every route class where the tenant's routing policy selects an OpenAI model; the batch lane (judge only) and prompt caching are enabled for this endpoint.

code
Region of processing

OpenAI default API endpoint, US processing. An EU-region endpoint exists on the provider side but is not configured (no EU door at launch, epic #597).

code + decision
Data categories

Same categories as Anthropic (the router sends the same redacted wire to whichever endpoint the policy selects).

code
Retention on the provider side
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Zero-data-retention / training opt-out

Repo record (memo §8): API traffic not used for training by default

En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

owner
Contractual basis
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Date last verified
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification

Mistral

Actif
Détails pour Mistral
ChampValeurSource
Purpose

Model inference for agent runs on every route class where the tenant's routing policy selects a Mistral model. No batch lane, no prompt caching, no extended thinking on this endpoint (registry capabilities are empty), so no cached prefixes exist at the provider.

code
Region of processing

Mistral hosted API, EU-default hosting (memo §8).

repo record
Data categories

Same categories as Anthropic.

code
Retention on the provider side
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Zero-data-retention / training opt-out
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Contractual basis
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Date last verified
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification

Vercel AI Gateway

Conditionnel

Not a sub-processor by default. The gateway host is admitted by the router only when EQUALI_VERCEL_AI_GATEWAY_ENABLED is true and the operator declares explicitly marked gateway entries in EQUALI_ROUTER_ENDPOINTS (ADR-0089; GTM plan §15). The default is off and GA does not depend on it. When an operator enables it, this section becomes a live row and must be completed before the flag is flipped:

Détails pour Vercel AI Gateway
ChampValeurSource
Purpose

Transport proxy in front of an upstream model provider (one of the three above, or another declared endpoint). Never on the batch lane.

code
Region of processing

Vercel infrastructure (US/global); the upstream provider's own region still applies behind it.

code
Data categories

Identical to whichever upstream provider the gateway entry fronts; the gateway sees the full redacted wire.

code
Retention on the provider side
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Zero-data-retention / training opt-out
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Contractual basis
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Date last verified
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification

Google

Autorisation en attente
Détails pour Google
ChampValeurSource
Purpose

Model inference for agent runs on every route class where the tenant's routing policy selects a Google model, once cleared. Prompt caching is enabled for this endpoint (no batch lane).

code
Region of processing

Google's default Gemini API endpoint, US processing. No EU-resident door exists at launch (epic #597: first markets are US and Canada).

code + decision
Data categories

Same categories as Anthropic (the router sends the same redacted wire to whichever endpoint the policy selects).

code
Retention on the provider side
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Zero-data-retention / training opt-out
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Contractual basis
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Date last verified
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification

xAI

Autorisation en attente
Détails pour xAI
ChampValeurSource
Purpose

Model inference for agent runs on every route class where the tenant's routing policy selects an xAI model, once cleared. Prompt caching is enabled for this endpoint (no batch lane).

code
Region of processing

xAI's default API endpoint (gRPC transport), US processing. No EU-resident door exists at launch (epic #597: first markets are US and Canada).

code + decision
Data categories

Same categories as Anthropic (the router sends the same redacted wire to whichever endpoint the policy selects).

code
Retention on the provider side
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Zero-data-retention / training opt-out
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Contractual basis
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification
Date last verified
En cours de vérification

Nous n’avons pas encore confirmé cette valeur. Revenez consulter cette page une fois la vérification terminée.

En cours de vérification

Où cela est documenté

Ces politiques et pages font référence aux mêmes sous-traitants.

Où cela est documenté
DocumentCe que cela couvre
Supabase (Postgres, Auth)The source rows the data blocks are built from, agent run records, invocation rows with token counts and cost, injection-screen records and hashes of untrusted inputs (never prompt text).
Temporal CloudWorkflow histories for agent runs: activity inputs/outputs, which include the composed prompt blocks and model outputs for the history retention period.
Logfire (US sink)Traces and metrics for every model call: token counts, cost, route decision, redaction counts. Prompt/completion content only when both the router flag and the tenant agents.telemetry.content_capture flag are on.
Deploy target (AWS / Azure / GCP / managed)Runs the router, worker and API containers that hold provider keys in the platform secrets manager; no AI data at rest beyond container logs (redacted).
Payment processors, store platforms, SlackNot AI sub-processors: no model output is sent to them and no AI provider receives their raw payloads (processor payloads are a declared untrusted input of the remediation proposer but reach the model only as normalised status rows, never as the raw webhook body).

Comment les données circulent

Cette section explique ce qui quitte les systèmes de Lumtry, où cela va et ce qui demeure à l’interne.

Comment une requête quitte Lumtry

  1. A worker activity (or an API service) composes the prompt from labelled blocks. Each block is a DataBlock(source, text, trusted); build_prompt renders it on the wire as <data source="<label>" trusted="true|false">…</data> so the model, the redaction layer and the compliance record all see the same label. Trusted blocks are merchant- or platform-sourced (policy text, ids, aggregates); untrusted blocks are shopper-authored free text and prior model output.
  2. Untrusted blocks are screened first where the agent declares them (AgentSpec.untrusted_inputs). The injection screen runs the keyword rules and, when the tenant's screen settings allow it, one screen_injection model call whose wire wraps the text as <untrusted_data source="<label>">…</untrusted_data>; that call uses the same router route as every agent call (POST /v1/agents/{agent_id}/model-request), so step 3 applies to it too. A flagged block is withheld from the author agent (dispute reads return empty rows; the case note agent runs without the history block). The screen record stores a hash of each untrusted input, never the text.
  3. The router redacts once, before any dispatch (, redact_agent_messages). Every string on the wire - user prompt, every data block, every tool return, every prior model turn on multi-step runs - passes the universal redact_string baseline from:
  4. secret shapes (provider keys, bearer tokens, webhook secrets) → [REDACTED];
  5. Luhn-valid 13-19 digit sequences (card numbers) → [REDACTED];
  6. email addresses → the literal [EMAIL]@[REDACTED] (the whole address, local-part and domain, is replaced; nothing of the address survives). Blocks whose label appears in the tenant policy's agents.pii.redact_by_source map are additionally routed through the field-wise redact_block hints for that label. The default map is {} (migration 122), so at launch the baseline is what every block gets.
  7. Dispatch goes to the endpoint the tenant's routing policy selects among the sub-processors (Anthropic, OpenAI, Mistral, Google, xAI, plus the optional Vercel AI Gateway transport); the same redacted wire goes to whichever endpoint wins, regardless of vendor. Google and xAI carry compliance_cleared=false in the shipped platform policy (feature 581), so the routing policy and publish gate both refuse to select either vendor for production agent traffic until an operator records that vendor's sub-processor row and flips the flag; the tables below describe what would be sent, not that it is currently sent.
  8. Model output comes back into the worker activity, is validated against the agent's typed output, and is persisted as a proposal or draft. Output never reaches a processor, store platform or Slack unreviewed; it is text or a proposal row an operator acts on.

Identifiants que nous pseudonymisons

Only platform-issued UUIDs cross: refund_case_id, dispute_case_id, policy_version_id, agent_run_id, discrepancy and execution row ids. They identify a row inside the tenant's own data and carry no shopper identity. The correlation id is an internal header between worker, router and API; it is not placed in the prompt and is not sent to the provider. Email addresses inside free text are not pseudonymised but removed outright ([EMAIL]@[REDACTED]), so no address-derived pseudonym reaches a provider either.

Ce qui ne quitte jamais Lumtry

FieldWhy it cannot reach a provider
Processor tokens, payment-method ids, external_reversal_reference bodiesNo block reads them; the remediation execution view exposes only status, amount, method and an opaque reference id. Secret-shaped strings are additionally scrubbed by the baseline.
Raw card data / PANNever stored (CLAUDE.md security must-haves); any Luhn-valid 13-19 digit run that appears in free text is replaced by [REDACTED] before dispatch.
Full email local-part (and the domain)Baseline replaces every email address on every wire string with [EMAIL]@[REDACTED].
API keys, bearer tokens, webhook secrets, request headersSecret-shape regexes on every wire string; the observability layer's denied header set strips them from any logged request; provider credentials live only in router scope (ADR-0004).
Raw processor / store webhook payloadsThe remediation proposer declares processor_payloads as an untrusted input class, but its read tools return normalised rows (remediation.execution_status etc.), never the stored webhook body.
Shopper account identifiers (external_customer_id, order emails, addresses)Used server-side as lookup keys (prior-transaction summary, order lookup) and never rendered into a block; the summary sent is a count, first/last date and total.
Prompt and completion text into telemetryOff unless both the router flag and the tenant flag are on (§4).

Catégories d’acheminement

Catégorie d’acheminement screen

AgentBlock / inputTrustedContentRedaction before the call
screen_injectionscreened_text (declared input); on the wire the label is the block being screened: case_history, shopper_communication, or a remediation read-tool id (remediation.case_timeline, remediation.execution_status, remediation.discrepancy, remediation.audit_trail, remediation.pinned_policy, remediation.compensation_trace)noThe untrusted text the author agent is about to receive, wrapped as <untrusted_data source=…>.Baseline (the screen call goes through the router like any agent call).

Catégorie d’acheminement classify

AgentBlock / inputTrustedContentRedaction before the call
classify_refund_caserefund_reason_textnorefund_cases.refund_reason free text, stripped.Baseline; redact_by_source hint if configured.
classify_refund_casecustomer_localeyesrefund_cases.customer_locale (BCP-47 tag or en-US).None needed.
resolve_sentimentmessage_textnoComposed from portal_submissions.note and refund_cases.refund_reason.Baseline; redact_by_source hint if configured.
resolve_sentimentcustomer_localeyesAs above.None needed.
narrate_abuse_riskrefund_caseyesA summary composed from abuse_risk_assessments.features (bands, counts, signal names) plus the recorded decision line. No shopper free text.Baseline.
retention_offer_copybrand_name, order_number, offers, currency, localeyesMerchant brand name, the order number, offer parameters (type, bonus/partial percent) as JSON, ISO currency, locale. No shopper free text (the agent declares no untrusted inputs).Baseline.

Catégorie d’acheminement author

AgentBlock / inputTrustedContentRedaction before the call
case_note_referencerefund_caseyesThe refund_case_id only.None needed.
case_note_referencecase_historynoportal_submissions.note + refund_cases.refund_reason, screened first; withheld when flagged.Injection screen, then baseline; redact_by_source hint if configured.
dispute_evidence_narrativeshopper_communication (tool dispute.shopper_communications)noportal_submissions.note with created_at, screened first; empty rows when flagged.Injection screen, then baseline (tool returns are wire strings).
dispute_evidence_narrativeevidence_sections (tool dispute.evidence_sections)yesdispute_evidence_packs.sections_jsonb: per-section status, source names and merchant-assembled facts.Baseline.
dispute_evidence_narrativecase_timeline (tool dispute.case_timeline)yesaudit_events category, timestamp and summary for the case.Baseline.
dispute_evidence_narrativepolicy_version_text (tool dispute.policy_version_text)yesPinned policy version: rule names, outcomes, explanation templates, published date.Baseline.
dispute_evidence_narrativeprior_transaction_summary (tool dispute.prior_transaction_summary)yesCount, first/last timestamp, total in minor units and currency of the shopper's prior cases; the customer id is the lookup key and is not sent.Baseline.
remediation_proposerinitial promptyesrefund_case_id and, for discrepancy targets, discrepancy_id, stated as plain ids.None needed.
remediation_proposerprocessor_payloads, shopper_text, case_notes (declared input classes)noReached only through the read tools below; each tool return is screened as a block labelled with the tool id and withheld when flagged.Injection screen, then baseline.
remediation_proposerremediation.case_timeline, remediation.audit_trailscreenedaudit_events id, category, timestamp, summary.Injection screen, then baseline.
remediation_proposerremediation.execution_statusscreenedExecution rows: id, status, amount in minor units, currency, method, opaque reversal reference; processor view status only.Injection screen, then baseline.
remediation_proposerremediation.discrepancyscreenedDiscrepancy id, status, kind, amount, currency.Injection screen, then baseline.
remediation_proposerremediation.pinned_policyscreenedPinned policy text (rule names/outcomes).Injection screen, then baseline.
remediation_proposerremediation.compensation_tracescreenedCompensation step name, status, attempt timestamp.Injection screen, then baseline.

Catégorie d’acheminement critic

AgentBlock / inputTrustedContentRedaction before the call
dispute_narrative_criticdraft_narrativenoThe author agent's draft narrative (prior model output, treated as untrusted by the family rule).Baseline.

Catégorie d’acheminement reason

AgentBlock / inputTrustedContentRedaction before the call
propose_policy_rulestask_inputyesJSON of the merchant's pasted policy text, workspace currency and locale (policy import).Baseline.
suggest_policy_rulestask_inputyesJSON of channel scope, channel roster, currency, lookback window, current rule summaries and evidence groups (aggregate bands only; no case free text, no shopper ids).Baseline.
policy_backtest_explainerget_backtest_summary (tool policy_backtest.get_backtest_summary)yesThis run's stored backtest summary (policy_backtests.summary_jsonb): case counts, transitions, approval-queue load before/after, and per-rule attribution, all computed by the pure equali_policy_engine.backtest evaluator before the run starts. No shopper free text.Baseline.
policy_backtest_explainerdraft_rule_text (tool policy_backtest.get_draft_rules)noA draft rule's name and explanation_template: merchant-authored free text. Every other field the same tool returns for a rule (rule_id, condition_json, outcome, priority) is a platform value the pure evaluator already validated.Baseline.

Catégorie d’acheminement judge

AgentBlock / inputTrustedContentRedaction before the call
eval_judgerubricyesThe per-agent grading rubric (platform text).None needed.
eval_judgesampled_outputnoThe sampled agent run's output and the facts it was produced from, as already redacted for that run.Baseline (runs on the batch lane where the endpoint supports it).

Télémétrie

Every model call emits a span and an invocation row with token counts, cost, route decision, endpoint, effort and redaction counters. Prompt and completion content is attached only when both RouterSettings.equali_ai_content_capture_enabled and the tenant policy flag agents.telemetry.content_capture are true; the attached content is passed through redact_key_value first. Either flag off means no content in Logfire. Event payloads (gen_ai events) carry no prompt, completion or provider response body.

Conservation des données

Les périodes de conservation varient selon le fournisseur et le type de données. La section de chaque sous-traitant ci-dessus indique la ligne de conservation de ce fournisseur ; voici ce que signifient ces réglages.

Provider-side retention is per sub-processor in (owner input). Platform-side, the composed prompt blocks live in Temporal workflow history for the history retention period and the persisted proposal/draft rows live under the tenant's normal data lifecycle and DSAR export. Prompt text is not stored in agent_runs, ai_invocations or the injection-screen records; only hashes, counts and costs are.

Consultez la ligne de conservation dans la section des sous-traitants de chaque fournisseur ci-dessus pour connaître sa période précise.

Nous joindre

Des questions sur cette page, vos données ou la façon dont Lumtry utilise l’IA ? Communiquez avec l’une des équipes ci-dessous.

Confidentialité
privacy@agnotiq.com