Lucnox Orbit Trust Center

Security posture, data flow and beta limitations.

This Trust Center separates implemented website controls from Microsoft integration validation work and planned product controls. It is not a certification, audit report or legal compliance opinion.

Last reviewed
2026-07-17
Implemented controls
3
Planned controls
5

Product maturity

Private beta limitations are part of the trust model.

validation

No Microsoft connector in this repository

The public website documents the intended assessment model, but the repository does not contain a tenant scan engine, Graph client or app registration configuration.

planned

Runtime governance is not available

Continuous monitoring, approval workflows, policy evaluation and enforcement remain roadmap capabilities unless separately included in a validated pilot.

planned

No published certifications or SLAs

SOC 2, ISO 27001, penetration tests, formal SLAs and incident response commitments are not documented as completed.

planned

Retention and deletion are open decisions

Specific retention periods, deletion workflows, backup expiry and offboarding processes must be finalized before production customer use.

planned

Security and privacy contacts are launch blockers

No verified security@, privacy@ or general contact mailbox is documented in this repository.

Architecture diagram

Consent, processing and reporting boundaries.

Text equivalent: Customer browser talks to the Orbit frontend. The frontend submits assessment requests to the Orbit backend. Future Microsoft tenant connections should happen between the Orbit backend and Microsoft Identity Platform and APIs. Normalized metadata would be stored in Orbit storage and used for reporting or export. Tokens and secrets must stay server-side.

This diagram is a documented architecture target for Microsoft tenant discovery. Current implemented repository scope is the public website, form endpoint and email delivery.

Microsoft permissions

No Microsoft permission is undocumented.

Microsoft permission register
PermissionTypeAccessStatusPurpose
No production Microsoft permission configured in this repositoryapplicationreadvalidationDocuments the current verified state: the public website repository has no Microsoft app registration, Graph scopes, Azure resource permissions or token storage implementation.

Full details are published on the Microsoft integrations page.

Security controls

Implemented, partial and planned controls.

Implemented

Secure Development

Baseline website security headers

implemented

The website sets HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Cross-Origin-Opener-Policy and Permissions-Policy headers.

Authorization

Assessment form origin checks

implemented

The assessment endpoint checks allowed origin/host values and rejects cross-site submissions.

Secret Management

Server-side email delivery

implemented

Resend API credentials are read from server-side environment variables and are not sent to the browser.

Partially implemented / in validation

Monitoring

Assessment form abuse controls

partially-implemented

The form endpoint uses payload limits, honeypots, submit timing checks and in-memory rate limiting.

  • Rate limiting is in-memory and not a distributed production abuse-control system.

Vulnerability Management

Dependency management

partially-implemented

Dependencies are pinned in package-lock.json and build tooling is present. A formal vulnerability management process is not documented.

Planned before broader product use

Token Handling

Microsoft token handling

planned

No Microsoft OAuth, consent, refresh-token or token-storage implementation exists in this website repository.

  • Must be designed and reviewed before any tenant connection.

Tenant Isolation

Tenant-scoped product data separation

planned

Tenant-scoped processing is a private-beta architecture requirement, but no product tenant database or row-level separation is implemented in this website repository.

  • No Row-Level Security, tenant partitioning, object storage separation or cross-tenant tests are present.

Audit Trail

Evidence integrity

planned

Current public language is limited to timestamped evidence records with source references. Cryptographic tamper evidence is not implemented.

  • No append-only storage, hash chain, signatures or external anchoring exists in this repository.

Data Retention

Retention and deletion

planned

Retention periods, deletion workflows and backup expiry are open founder/legal decisions.

Incident Response

Incident response process

planned

No public incident response process, security contact or response-time commitment is configured in this repository.

Tenant isolation

Tenant-scoped processing is a beta architecture requirement, not a completed claim.

Current website scope does not include a product tenant database, Microsoft scan records, object storage, queues, search indexes or exports. Therefore the site does not claim full tenant isolation.

Before customer tenant processing, Lucnox must document the tenant identifier model, database partitioning or Row-Level Security, query filters, cache separation, log separation, export access, support access, administrator access, break-glass rules and cross-tenant tests.

Data processing

Data categories, storage and retention status.

Assessment request form data

Source: Website visitor

Stored: yes
Purpose
Qualify private beta assessment fit and route the request.
Storage location
Email delivery through Resend and recipient mailbox; no application database in this repository.
Sensitivity
Business contact data and free-text assessment context
Retention
Open decision; no fixed retention period is defined in this repository.
Deletion
Manual deletion process not yet documented.
Access
Recipient mailbox and Resend operational systems, depending on configured environment.
  • Free-text fields may contain sensitive customer context; users are asked not to submit secrets.

Website technical logs

Source: Vercel hosting platform and browser requests

Stored: yes
Purpose
Operate, debug and secure the website.
Storage location
Hosting provider logs; exact region and retention are not defined in this repository.
Sensitivity
Operational metadata such as IP address, user agent, request path and error diagnostics
Retention
Open decision / provider-controlled unless configured separately.
Deletion
Provider and account-level processes not documented in this repository.
Access
Vercel project/account access.
  • Formal log access review and retention policy are not documented.

Microsoft tenant discovery metadata

Source: Microsoft tenant APIs

Stored: not-yet-implemented
Purpose
Planned authority, ownership and permission analysis for the private beta assessment.
Storage location
Not implemented in this website repository.
Sensitivity
Security-sensitive tenant metadata and possible personal data
Retention
Open decision before tenant connection.
Deletion
Disconnect, offboarding and deletion process must be defined before activation.
Access
Not implemented; future access model must be role-based and tenant-scoped.
  • No Microsoft connector, storage model or tenant isolation tests exist in this repository.

Assessment reports and evidence exports

Source: Orbit assessment process

Stored: not-yet-implemented
Purpose
Provide reviewable evidence and prioritized findings to the customer.
Storage location
Not implemented in this website repository.
Sensitivity
Confidential customer security and governance findings
Retention
Open decision.
Deletion
Report deletion process must be defined before delivery.
Access
Not implemented.
  • Synthetic report concepts must not be presented as completed audit packages.

Subprocessors

Documented providers and open facts.

Subprocessor register
ProviderPurposeStatusData categoriesOpen notes
VercelWebsite hosting, CDN, serverless functions and deployment platformactiveWebsite requests, technical logs, assessment form API trafficProcessing region and account-level DPA status are not documented in this repository.
ResendAssessment request and confirmation email deliveryactiveName, work email, company, role, assessment request contentUsed when RESEND_API_KEY and email environment variables are configured.
GitHubSource code hosting and deployment source controlactiveSource code, deployment metadata, repository access recordsNo customer tenant data should be committed to the repository.
MicrosoftFuture customer identity, consent and tenant data sourceplannedMicrosoft tenant metadata planned after consentNo Microsoft tenant connection is implemented in this website repository.

Evidence integrity

Timestamped source references now; tamper evidence later.

Orbit does not claim immutable evidence. The current safe maturity statement is: timestamped evidence records with source references. Append-only behavior, versioned evidence history, cryptographic tamper evidence or external anchoring are not implemented in this repository.

Vulnerability disclosure

Security reporting process.

A verified security contact mailbox is not documented in this repository. Until that is finalized, do not publish invented addresses such as security@lucnox.com or privacy@lucnox.com.

Planned disclosure guidance: include affected URL, reproduction steps, impact, screenshots or logs without secrets, and your preferred contact method. Do not access, modify, delete or disclose data that does not belong to you. No bug-bounty payment, response time or safe-harbor term is promised until formally approved.

Compliance guardrail

Technical evidence, not legal determination.

Orbit provides technical discovery, governance signals and evidence workflows. It does not provide legal advice, certification or a complete determination of compliance with NIS2, the EU AI Act or other laws.

Microsoft scope

Current integration statuses at a glance.

  • Microsoft Entra IDvalidation
  • Microsoft Graphvalidation
  • Copilot Studioplanned
  • Power Platform, Power Automate and Power Appsplanned
  • Microsoft Purviewplanned
  • Microsoft Defenderplanned
  • Microsoft Teams and SharePoint Onlineplanned
  • Azure AI and Azure OpenAIvision
  • Logic Apps and Managed Identitiesvision