Security & Vulnerability Disclosure
Last updated: 5 August 2026
We welcome reports from security researchers. This page explains how to report a vulnerability in LumiaChatFlow and what you can expect from us.
Reporting a vulnerability
Email security@lumiachatflow.com with:
- what you found and where — URL, endpoint, or component;
- how to reproduce it, step by step;
- what an attacker could achieve with it;
- any proof-of-concept you are willing to share.
Please report in English. We will acknowledge your report within 3 business days and keep you updated while we investigate.
Scope
In scope: the LumiaChatFlow application (app.lumiachatflow.com), the marketing site
(lumiachatflow.com), the embeddable chat widget, and our public APIs.
Out of scope:
- our customers' own websites, and the content their agents are trained on;
- PayPro Global's checkout and billing systems — report those to PayPro Global directly;
- findings from automated scanners without a demonstrated impact;
- volumetric denial-of-service, spam, or social engineering of our staff or customers;
- issues requiring a rooted or physically compromised device, or outdated browsers.
Please do not
- access, modify, or delete data belonging to anyone but yourself — create your own free account to test against;
- degrade the service for others, or run load or stress tests;
- use a finding for anything beyond demonstrating it;
- publish details before we have had a reasonable chance to fix the issue.
Our commitment to you
If you follow this policy in good faith, we will not pursue legal action against you for your research, and we will treat your report as an authorized contribution to the security of the service. We will credit you when we publish a fix, if you would like us to.
We do not currently operate a paid bug-bounty programme.
Coordinated disclosure
We aim to remediate confirmed vulnerabilities promptly, with severity driving the timeline. We ask that you allow us 90 days before public disclosure, and we will work with you if a fix needs longer.
How the service is built
A short, factual summary of the security posture behind LumiaChatFlow:
| Hosting | Google Cloud Platform, primary region europe-west1 (Belgium) — for our own storage; the AI search layer carries no regional guarantee, see Privacy Policy §6 |
| Data in transit | TLS on all endpoints |
| Data at rest | Per-tenant envelope encryption — AES-256-GCM data keys wrapped by Google Cloud KMS |
| Tenant isolation | Data partitioned per tenant; cross-tenant access treated as a hard constraint |
| Authentication | Email verification required at sign-up; two-factor authentication and session controls available; no social login |
| Access control | Role-based access within a workspace; platform-admin operations gated on a separate, non-self-serviceable claim |
| Audit logging | Security and compliance events recorded, with high-severity events published for alerting |
| Data deletion | Self-service account deletion with a grace period, plus GDPR erasure workflows that delete tenant data, its encryption keys, and the search index built from the content |
| AI models | No training or fine-tuning on customer data; our AI providers are contractually bound not to use paid-tier content to improve their models |
security.txt
The following is published at https://lumiachatflow.com/.well-known/security.txt:
Contact: mailto:security@lumiachatflow.com
Contact: https://lumiachatflow.com/security
Policy: https://lumiachatflow.com/security
Preferred-Languages: en
Canonical: https://lumiachatflow.com/.well-known/security.txt
Expires: 2027-07-27T00:00:00.000Z