Last updated 25 August 2026
Security Policy
Current LumicSec operating policy. Mandatory rights under applicable law continue to apply, and any enterprise or jurisdiction-specific commitment must be expressly agreed in writing.
1. Authentication and tenant authorization
LumicSec uses authenticated workspace access, server-side authorization and ownership checks, and database row-level security for protected product data. Access to a customer asset or report is expected to remain scoped to the authenticated/authorized account or an explicitly created read-only share mechanism.
2. Authorized scanning boundaries
Deeper review remains gated behind ownership or permission controls, plan eligibility and Verified Scan Access where required. Standard/public scanning is designed around safe public checks. Standard workflows avoid brute force, login bypass, destructive exploitation, denial-of-service behavior and private-data access, and Deep Scan does not treat destructive mutation as an ordinary evidence-gathering method.
3. Secret and bearer-token minimization
Scan Access and Secure Client Report Links are designed to minimize persistent bearer secrets. The server-side credential/link records retain cryptographic hashes and short prefixes/state rather than the raw Scan Access or client-report bearer token. Scan Access is scoped to the exact authorized origin, and the secret must not be forwarded to unrelated or cross-origin destinations. Rotation/revocation controls are used to invalidate access when needed.
4. Transport and browser security controls
LumicSec production web traffic is served over HTTPS and uses browser-facing security headers including HSTS, Content Security Policy, frame protection, content-type protection, Referrer-Policy and Permissions-Policy. This public policy does not make an unsupported claim about a particular provider's at-rest encryption or backup configuration.
5. Abuse, quota and service protections
The service uses authorization, plan/quota enforcement and abuse-protection controls to reduce unauthorized or excessive use. These controls are defensive boundaries, not a promise that every automated attack or abuse attempt can be prevented.
6. Development and dependency changes
Application changes are validated through source control and automated CI/build checks before normal production release. Security and dependency updates are applied as supported releases become available and are verified against the product rather than being represented as risk-free before testing.
7. Security incidents
LumicSec investigates material security issues affecting the service and takes containment/remediation steps appropriate to the evidence and available controls. Customer notification is handled where required by law or reasonably necessary for an affected service relationship. This policy does not promise a fixed incident-notification or recovery deadline.
8. Responsible disclosure
Security issues affecting LumicSec should be submitted through the contact channel as a responsible disclosure. Do not place credentials, raw Scan Access tokens, private keys, payment secrets or unrelated personal data in a disclosure unless LumicSec specifically requests a safe transfer method.