Make monday.com work with Microsoft 365 & SharePoint →
Lumin logo

Lumin

Lumin

100 installs, since August 13, 2024.   9 installs/month.   Updated August 13, 2024.

Free plan available No touch
Gallery image Gallery image Gallery image Gallery image Gallery image

Create, send and sign contracts easily in monday.com

With Lumin, user can create, send and track Lumin contracts within [monday.com](http://monday.com/). Users can track the status of contracts without leaving monday.com


What problems are you solving for your users?

- **Manual Signature Collection:** Users on monday.com often need to collect signatures for approvals, contracts, and other documents. Traditionally, this involves manual processes that are time-consuming, requiring printing, signing, scanning, and emailing.

- **Lack of Document Tracking and Visibility:** Tracking the status of documents can be challenging. Users may not know if a document has been signed, where it is in the approval process.

What are the benefits or potential results users will receive from using your app?

- **Streamlined Signature Collection:** With Lumin Sign integrated into monday.com, users can easily send documents for e-signature without leaving the platform. This integration eliminates the need for manual steps, saving time and reducing the risk of errors.

- **Document Status Updates:** The integration allows users to track the status of their documents in real-time. They can see who has signed, who still needs to sign, and receive notifications for any action required.

**Scenario:** A sales team using monday.com to manage their sales pipeline often needs to send contracts to clients for approval and signature.

**Use Case:** With the Lumin Sign integration, the sales members can create a contract within monday.com, attach it to a task, and send it directly to the client for e-signature. The platform tracks the status of the contract, and updating the signature’s status in monday.com.


File limitation:

- Users can upload a maximum of 5 files per task.

- The maximum file size must be less than 20MB.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

No

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
We are using Ory (https://www.ory.sh/) for identity management and build OAuth2 flow based on Ory. All OAuth2 implementation is

Does the app protect against mass parameter assignment attacks?

Yes
We do not send input directly from the client into the database.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
All user data is validated via class-validator, all input is validated before passing to any function on our service.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
We are using Ory service (https://www.ory.sh/) for identity management, which includes protection against CSRF. All requests on our backend use Bearer tokens, ensuring that CSRF attacks are not possible.

Does the developer have mechanisms to notify monday.com in case of a security breach?

No
In the event of a security breach, we will immediately disable all features on Monday.com via the backend. We will then fix the issue as soon as possible before reopening the features.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
For critical and high-priority issues, we will fix them immediately. Medium-priority issues will be addressed within 2-3 days, and low-priority issues will be resolved within 1-2 weeks.”

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Yes
https://www.luminpdf.com/soc2/

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
https://www.luminpdf.com/security/

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

Not answered

Where does the app store the app data?

Not answered

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
We are using Datadog for logging and utilizing their filters to prevent logging of sensitive information.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Each user’s data is stored in a separate record in our database.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
We use Google login, TOTP (Time-Based One-Time Password) and whitelisted IP (VPN) for authentication to secure critical resources for employees.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Only CEO can have access to customer data

Reviews

No reviews yet.

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 10000568App ID: 10164420Listing updated: September 8, 2024