Security
Security at Lumora
Lumora only scans publicly accessible pages and does not bypass logins, paywalls, robots controls, or private content. Submitted URLs and crawled pages are treated as untrusted from the start.
What Lumora scans
- Public HTTP and HTTPS pages
- Visible text, metadata, headings, links, and structured data
- Public signals needed for launch readiness and buyer understanding
What Lumora does not scan
- Login-only pages
- Paywalled or private content
- Internal networks, localhost, metadata services, or private IP ranges
Crawler safety
- SSRF and private-network blocking
- Unsafe redirect checks
- Public-page-only policy and bounded crawl limits
Data handling
- Submitted URLs and crawled content are treated as untrusted
- Reports show bounded evidence snippets, not raw debug output
- Payment secrets and private keys are never part of report content
AI output safety
- No LLM calls in the current deterministic analysis path
- Prompt injection is treated as untrusted website content
- Recommendations must stay evidence-based and explainable
Limitations
- Lumora is not a penetration test
- Lumora is not a full security audit
- Security readiness checks are launch-readiness signals only