Last updated 25 August 2026

Security Policy

Current LumicSec operating policy. Mandatory rights under applicable law continue to apply, and any enterprise or jurisdiction-specific commitment must be expressly agreed in writing.

1. Authentication and tenant authorization

LumicSec uses authenticated workspace access, server-side authorization and ownership checks, and database row-level security for protected product data. Access to a customer asset or report is expected to remain scoped to the authenticated/authorized account or an explicitly created read-only share mechanism.

2. Authorized scanning boundaries

Deeper review remains gated behind ownership or permission controls, plan eligibility and Verified Scan Access where required. Standard/public scanning is designed around safe public checks. Standard workflows avoid brute force, login bypass, destructive exploitation, denial-of-service behavior and private-data access, and Deep Scan does not treat destructive mutation as an ordinary evidence-gathering method.

3. Secret and bearer-token minimization

Scan Access and Secure Client Report Links are designed to minimize persistent bearer secrets. The server-side credential/link records retain cryptographic hashes and short prefixes/state rather than the raw Scan Access or client-report bearer token. Scan Access is scoped to the exact authorized origin, and the secret must not be forwarded to unrelated or cross-origin destinations. Rotation/revocation controls are used to invalidate access when needed.

4. Transport and browser security controls

LumicSec production web traffic is served over HTTPS and uses browser-facing security headers including HSTS, Content Security Policy, frame protection, content-type protection, Referrer-Policy and Permissions-Policy. This public policy does not make an unsupported claim about a particular provider's at-rest encryption or backup configuration.

5. Abuse, quota and service protections

The service uses authorization, plan/quota enforcement and abuse-protection controls to reduce unauthorized or excessive use. These controls are defensive boundaries, not a promise that every automated attack or abuse attempt can be prevented.

6. Development and dependency changes

Application changes are validated through source control and automated CI/build checks before normal production release. Security and dependency updates are applied as supported releases become available and are verified against the product rather than being represented as risk-free before testing.

7. Security incidents

LumicSec investigates material security issues affecting the service and takes containment/remediation steps appropriate to the evidence and available controls. Customer notification is handled where required by law or reasonably necessary for an affected service relationship. This policy does not promise a fixed incident-notification or recovery deadline.

8. Responsible disclosure

Security issues affecting LumicSec should be submitted through the contact channel as a responsible disclosure. Do not place credentials, raw Scan Access tokens, private keys, payment secrets or unrelated personal data in a disclosure unless LumicSec specifically requests a safe transfer method.

LumicSec provides security decision-support information, not a guarantee of complete security or legal compliance. Use the service only with proper authorization.