Security

Security at Lumora

Lumora only scans publicly accessible pages and does not bypass logins, paywalls, robots controls, or private content. Submitted URLs and crawled pages are treated as untrusted from the start.

What Lumora scans

  • Public HTTP and HTTPS pages
  • Visible text, metadata, headings, links, and structured data
  • Public signals needed for launch readiness and buyer understanding

What Lumora does not scan

  • Login-only pages
  • Paywalled or private content
  • Internal networks, localhost, metadata services, or private IP ranges

Crawler safety

  • SSRF and private-network blocking
  • Unsafe redirect checks
  • Public-page-only policy and bounded crawl limits

Data handling

  • Submitted URLs and crawled content are treated as untrusted
  • Reports show bounded evidence snippets, not raw debug output
  • Payment secrets and private keys are never part of report content

AI output safety

  • No LLM calls in the current deterministic analysis path
  • Prompt injection is treated as untrusted website content
  • Recommendations must stay evidence-based and explainable

Limitations

  • Lumora is not a penetration test
  • Lumora is not a full security audit
  • Security readiness checks are launch-readiness signals only