Security for the record you keep for decades.
For the security, IT, and procurement teams reviewing Lunr. Lunr is hosted and operated by an ISO/IEC 27001:2022 certified partner, runs in Australia and the US with your data in-region, signs staff in over SAML, keeps a full audit trail behind every controlled document, and lets you export your data at any time.
ISO/IEC 27001:2022 · Hosted in Australia and the US · SAML · Full audit trail · Export anytime
Hosted and operated to ISO/IEC 27001:2022.
Lunr is hosted and implemented by Onset Design, our hosting and implementation partner. Onset Design maintains ISO/IEC 27001:2022 compliance, and Lunr runs on that certified infrastructure.
The certification is held by Onset Design, the partner that hosts and operates Lunr.
Visit Onset Design- standard
- ISO/IEC 27001:2022
- certificate held by
- Onset Design
- scope
- Hosting and implementation
- Lunr's role
- Operated on certified infrastructure
// control domains
The hosting and operation of Lunr sit under Onset Design’s information security management system, certified to ISO/IEC 27001:2022. The standard organises its controls into organisational, people, physical, and technological themes, and the certified management system covers these domains.
Risks identified, assessed, and treated under a certified information security management system.
Access granted on need, reviewed, and revoked on change.
Encryption of data in transit and at rest governed by certified controls.
Backups maintained and tested under the ISMS.
Security incidents logged, managed, and reviewed.
Continuity of the service planned and exercised.
Downstream providers assessed and managed under the ISMS.
Certified controls over the hosting facilities.
Certification maintained through recurring external audit.
Hosted in Australia and the US, in the region you require.
Lunr is hosted in Australia and the US. Your instance sits in the region you require, and your data stays in-region. The choice is made at setup and holds for the life of the instance.
- Two hosting regions, Australia and the US, so your instance runs where your obligations require.
- Your data stays in-region, held in the region you select rather than moved between them.
- One region per instance, chosen at setup, so residency is settled before a document is loaded.
australia · united states · in-region residency · one region per instance
Staff sign in over SAML. External parties join as Collaborators.
Staff sign in over SAML with your identity provider, so accounts follow your joiner and leaver process. External parties join as Collaborators with controlled access, and permissions govern who sees and changes each controlled document.
- SAML sign-in through your identity provider, so access follows the accounts you already manage.
- External parties join as Collaborators with controlled access, scoped to the documents they need.
- Permissions govern who sees and changes each controlled document, down to the individual record.
saml sign-in · identity provider · collaborators · per-document permissions
- Staff
Sign in over SAML with your identity provider.
- Collaborators
External parties join with controlled access.
- Permissions
Govern who sees and changes each controlled document.
A full audit trail behind every controlled document.
A full audit trail sits behind every controlled document, filtered by lifecycle, revisions, or validation. Every workflow transition is recorded against a named person and a revision, so an approval is tied to who made it and against which copy. Export the record at any time for an ISO 19650 or compliance audit.
- A full audit trail on every controlled document, filtered by lifecycle, revisions, or validation.
- Every workflow transition recorded against a named person and a revision, never an email thread.
- Export the record at any time for an ISO 19650 or compliance audit.
full audit trail · named person and revision · lifecycle filters · export for audit
- AW-STR-DR-0142Rev C
In Review → Approved
C. Delaney · 14 Jul 2026
- AW-STR-DR-0142Rev B
Draft → In Review
A. Whitlock · 09 Jul 2026
- AW-MEP-SP-0007Rev A
Validated on upload
R. Mensah · 02 Jul 2026
Your documents remain yours.
Your documents remain yours, and you can export your data at any time. Take out documents and their metadata whenever you need to, so the record stays under your control and moving off Lunr is a task you can run yourself.
- Your documents remain yours, held on your instance and owned by your organisation.
- Export your data at any time, documents and metadata together, in a form you can take elsewhere.
- No lock-in on the way out, so a change of system is a task you plan and run, not one you negotiate.
your documents · export anytime · documents and metadata · no lock-in
Reviewed, selected, and run at scale.
Universities, utilities, infrastructure operators, life sciences, and metals and mining run their engineering record on Lunr, and Lunr has been selected through RFQ tender processes.
documents under management on Lunr, across higher education, utilities, infrastructure, life sciences, and metals and mining.
- Higher education
- Utilities
- Infrastructure
- Life sciences
- Metals and mining
Lunr has been selected through RFQ tender processes, including the University of Canberra, so the record stands up to the procurement review that precedes it.
Read the University of Canberra case studyRun your security review with us.
Send your security questionnaire and procurement due diligence, and we work through it with your security, IT, and procurement teams. Book a demo where a walkthrough helps the review along.
security questionnaires · procurement due diligence · directed to our team
Questions a procurement review asks.
Where data is hosted, who holds the certification, how due diligence runs, and what leaving looks like.
- Where is Lunr hosted, and where does our data live?
- Lunr is hosted in Australia and the US. Your instance sits in the region you require, and your data stays in-region. Choose the region during setup, and every document, model, and metadata record for your instance is held there.
- Who holds ISO/IEC 27001 certification?
- Lunr is hosted and implemented by Onset Design, our hosting and implementation partner. Onset Design maintains ISO/IEC 27001:2022 compliance, and Lunr runs on that certified infrastructure. The certification is held by Onset Design, the partner that hosts and operates Lunr.
- What does the ISO/IEC 27001 certification cover?
- The certification covers Onset Design's information security management system for the hosting and operation of Lunr. Under ISO/IEC 27001:2022, that management system applies controls across risk assessment and treatment, access control, cryptography for data in transit and at rest, backup and operations security, incident management, business continuity, supplier relationships, and physical and environmental security, and it is maintained through recurring independent audit. The standard organises these controls into organisational, people, physical, and technological themes.
- How do we run security and procurement due diligence?
- Send your security questionnaire through the contact page, and we work through it with your security, IT, and procurement teams. Lunr has been selected through RFQ tender processes, including the University of Canberra, so the documents a procurement review asks for are ready to hand over.
- How does access control work for staff and external parties?
- Staff sign in over SAML with your identity provider, so accounts follow your joiner and leaver process. External parties join as Collaborators with controlled access. Permissions govern who sees and changes each controlled document.
- Can we export our data if we leave?
- Yes. Your documents remain yours, and you can export your data at any time. Take out documents and their metadata whenever you need to, so the record stays under your control and moving off Lunr is a task you can run yourself.
- What audit trail does Lunr keep for compliance?
- A full audit trail sits behind every controlled document, filtered by lifecycle, revisions, or validation. Every workflow transition is recorded against a named person and a revision, and you can export the record at any time for an ISO 19650 or compliance audit.
Start your security review.
Send a security questionnaire to a team that knows what an audit trail, data residency, and an ISO 19650 record are, or book a demo and see the controls on your own documents.
ISO/IEC 27001:2022 · Hosted in Australia and the US · SAML · Full audit trail · Export anytime
- entity
- Lunr Labs Pty Ltd
- location
- Melbourne AU
- workspace
- documents.lunr.app
- rev
- 2026