LumiaChatFlow
FeaturesPricingSign inGet Started

Security & Vulnerability Disclosure

Last updated: 5 August 2026

We welcome reports from security researchers. This page explains how to report a vulnerability in LumiaChatFlow and what you can expect from us.

Reporting a vulnerability

Email security@lumiachatflow.com with:

  • what you found and where — URL, endpoint, or component;
  • how to reproduce it, step by step;
  • what an attacker could achieve with it;
  • any proof-of-concept you are willing to share.

Please report in English. We will acknowledge your report within 3 business days and keep you updated while we investigate.

Scope

In scope: the LumiaChatFlow application (app.lumiachatflow.com), the marketing site (lumiachatflow.com), the embeddable chat widget, and our public APIs.

Out of scope:

  • our customers' own websites, and the content their agents are trained on;
  • PayPro Global's checkout and billing systems — report those to PayPro Global directly;
  • findings from automated scanners without a demonstrated impact;
  • volumetric denial-of-service, spam, or social engineering of our staff or customers;
  • issues requiring a rooted or physically compromised device, or outdated browsers.

Please do not

  • access, modify, or delete data belonging to anyone but yourself — create your own free account to test against;
  • degrade the service for others, or run load or stress tests;
  • use a finding for anything beyond demonstrating it;
  • publish details before we have had a reasonable chance to fix the issue.

Our commitment to you

If you follow this policy in good faith, we will not pursue legal action against you for your research, and we will treat your report as an authorized contribution to the security of the service. We will credit you when we publish a fix, if you would like us to.

We do not currently operate a paid bug-bounty programme.

Coordinated disclosure

We aim to remediate confirmed vulnerabilities promptly, with severity driving the timeline. We ask that you allow us 90 days before public disclosure, and we will work with you if a fix needs longer.

How the service is built

A short, factual summary of the security posture behind LumiaChatFlow:

HostingGoogle Cloud Platform, primary region europe-west1 (Belgium) — for our own storage; the AI search layer carries no regional guarantee, see Privacy Policy §6
Data in transitTLS on all endpoints
Data at restPer-tenant envelope encryption — AES-256-GCM data keys wrapped by Google Cloud KMS
Tenant isolationData partitioned per tenant; cross-tenant access treated as a hard constraint
AuthenticationEmail verification required at sign-up; two-factor authentication and session controls available; no social login
Access controlRole-based access within a workspace; platform-admin operations gated on a separate, non-self-serviceable claim
Audit loggingSecurity and compliance events recorded, with high-severity events published for alerting
Data deletionSelf-service account deletion with a grace period, plus GDPR erasure workflows that delete tenant data, its encryption keys, and the search index built from the content
AI modelsNo training or fine-tuning on customer data; our AI providers are contractually bound not to use paid-tier content to improve their models

security.txt

The following is published at https://lumiachatflow.com/.well-known/security.txt:

Contact: mailto:security@lumiachatflow.com
Contact: https://lumiachatflow.com/security
Policy: https://lumiachatflow.com/security
Preferred-Languages: en
Canonical: https://lumiachatflow.com/.well-known/security.txt
Expires: 2027-07-27T00:00:00.000Z
LumiaChatFlow

AI-powered chatbot platform for businesses. GDPR-compliant and privacy-first.

A product by AxonLumia

Product

  • Features
  • Pricing

Company

  • About AxonLumia
  • Contact
  • LinkedIn

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Acceptable Use
  • DPA
  • Imprint
  • Security
  • Sub-processors
  • Widget Visitor Notice
AxonLumia

© 2026 AxonLumia. All rights reserved.

LumiaChatFlow is a registered trademark.