01Our approach
Lurion uses safeguards designed to protect the confidentiality, integrity, and availability of the Service and customer information in light of the risks involved. Our program is built around data minimization, access based on business need, credential and secret management, service monitoring, incident response, secure development practices, dependency maintenance, and review of relevant service providers.
Security is shared. No product can guarantee that a caller is genuine, an interaction is safe, or every threat will be detected. Lurion provides warnings and decision support; it does not authenticate callers, replace customer controls, or eliminate the need for human review and independent verification.
02Customer responsibilities
Customers should use strong, unique credentials and multifactor authentication where available; promptly remove access for departing users; grant only necessary permissions; keep devices and software updated; protect API keys and connected systems; independently verify sensitive requests; configure lawful monitoring and recording; and report suspected compromise promptly.
03Report a vulnerability
Email founders@lurion.org with “Security report” in the subject. Include the affected URL or component, potential impact, reproduction steps, supporting evidence, and a safe way to contact you. Do not include personal information or customer content unless necessary to explain the issue.
Please report privately and allow reasonable time for investigation and remediation before public disclosure. We will make a good-faith effort to acknowledge, assess, and address valid reports, but we do not promise a particular response or remediation timeline. We do not currently operate a paid bug-bounty program unless agreed in writing in advance.
04Responsible-disclosure rules
Good-faith research must avoid harm. Do not access, copy, alter, retain, or destroy data that is not yours; degrade or disrupt the Service; conduct denial-of-service, spam, social-engineering, phishing, physical-security, or third-party testing; use automated testing that creates excessive traffic; plant malware or persistence; demand payment; or violate privacy or other rights. Use the minimum testing needed, stop if you encounter sensitive data, and report the issue promptly.
Safe harbor. If you make a good-faith effort to follow this policy, Lurion will treat your research as authorized for purposes of applicable computer-access laws and does not intend to initiate legal action based solely on that research. This safe harbor does not authorize violations of law or third-party rights, and Lurion cannot bind third parties.
05Prohibited abuse
You may not use Lurion to facilitate unlawful activity; fraud, scams, or deceptive impersonation; unauthorized surveillance, monitoring, or recording; stalking, harassment, threats, discrimination, or exploitation; phishing, malware, credential theft, or unauthorized access; spam or abusive automation; evasion of security controls or usage limits; disruption or reverse engineering except where law permits; or decisions with significant legal or similarly serious effects without appropriate human review.
You also may not use the Service to create or distribute child sexual abuse material, non-consensual intimate imagery, content that meaningfully facilitates violence, or deceptive synthetic media intended to defraud or cause harm.
06Enforcement and reports
We may investigate suspected abuse; limit, suspend, or terminate access; preserve relevant records; and notify customers, affected parties, service providers, or authorities when permitted or required by law. Enforcement decisions may consider severity, intent, history, risk, and remedial action.
Report suspected misuse to founders@lurion.org with relevant dates, identifiers, links, and a concise description. Do not send unnecessary sensitive information. To request review of an enforcement decision, use the same address with “Appeal” in the subject.
07Incidents and limitations
If we determine that a security incident affects customer information, we will investigate and provide notice as required by applicable law and our agreements. Security information may be withheld when disclosure would create risk, compromise an investigation, or violate legal or contractual obligations.
This page describes our current approach and is not a warranty, service-level agreement, certification, or guarantee. Our Terms of Service govern use of the Service, and our Privacy Policy describes personal-information handling.
08Contact
Lurion LLC
founders@lurion.org