validation
No Microsoft connector in this repository
The public website documents the intended assessment model, but the repository does not contain a tenant scan engine, Graph client or app registration configuration.
Lucnox Orbit Trust Center
This Trust Center separates implemented website controls from Microsoft integration validation work and planned product controls. It is not a certification, audit report or legal compliance opinion.
Product maturity
validation
The public website documents the intended assessment model, but the repository does not contain a tenant scan engine, Graph client or app registration configuration.
planned
Continuous monitoring, approval workflows, policy evaluation and enforcement remain roadmap capabilities unless separately included in a validated pilot.
planned
SOC 2, ISO 27001, penetration tests, formal SLAs and incident response commitments are not documented as completed.
planned
Specific retention periods, deletion workflows, backup expiry and offboarding processes must be finalized before production customer use.
planned
No verified security@, privacy@ or general contact mailbox is documented in this repository.
Authentication and consent
Architecture diagram
Text equivalent: Customer browser talks to the Orbit frontend. The frontend submits assessment requests to the Orbit backend. Future Microsoft tenant connections should happen between the Orbit backend and Microsoft Identity Platform and APIs. Normalized metadata would be stored in Orbit storage and used for reporting or export. Tokens and secrets must stay server-side.
This diagram is a documented architecture target for Microsoft tenant discovery. Current implemented repository scope is the public website, form endpoint and email delivery.
Microsoft permissions
| Permission | Type | Access | Status | Purpose |
|---|---|---|---|---|
| No production Microsoft permission configured in this repository | application | read | validation | Documents the current verified state: the public website repository has no Microsoft app registration, Graph scopes, Azure resource permissions or token storage implementation. |
Full details are published on the Microsoft integrations page.
Security controls
Secure Development
The website sets HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Cross-Origin-Opener-Policy and Permissions-Policy headers.
Authorization
The assessment endpoint checks allowed origin/host values and rejects cross-site submissions.
Secret Management
Resend API credentials are read from server-side environment variables and are not sent to the browser.
Monitoring
The form endpoint uses payload limits, honeypots, submit timing checks and in-memory rate limiting.
Vulnerability Management
Dependencies are pinned in package-lock.json and build tooling is present. A formal vulnerability management process is not documented.
Token Handling
No Microsoft OAuth, consent, refresh-token or token-storage implementation exists in this website repository.
Tenant Isolation
Tenant-scoped processing is a private-beta architecture requirement, but no product tenant database or row-level separation is implemented in this website repository.
Audit Trail
Current public language is limited to timestamped evidence records with source references. Cryptographic tamper evidence is not implemented.
Data Retention
Retention periods, deletion workflows and backup expiry are open founder/legal decisions.
Incident Response
No public incident response process, security contact or response-time commitment is configured in this repository.
Tenant isolation
Current website scope does not include a product tenant database, Microsoft scan records, object storage, queues, search indexes or exports. Therefore the site does not claim full tenant isolation.
Before customer tenant processing, Lucnox must document the tenant identifier model, database partitioning or Row-Level Security, query filters, cache separation, log separation, export access, support access, administrator access, break-glass rules and cross-tenant tests.
Data processing
Source: Website visitor
Source: Vercel hosting platform and browser requests
Source: Microsoft tenant APIs
Source: Orbit assessment process
Subprocessors
| Provider | Purpose | Status | Data categories | Open notes |
|---|---|---|---|---|
| Vercel | Website hosting, CDN, serverless functions and deployment platform | active | Website requests, technical logs, assessment form API traffic | Processing region and account-level DPA status are not documented in this repository. |
| Resend | Assessment request and confirmation email delivery | active | Name, work email, company, role, assessment request content | Used when RESEND_API_KEY and email environment variables are configured. |
| GitHub | Source code hosting and deployment source control | active | Source code, deployment metadata, repository access records | No customer tenant data should be committed to the repository. |
| Microsoft | Future customer identity, consent and tenant data source | planned | Microsoft tenant metadata planned after consent | No Microsoft tenant connection is implemented in this website repository. |
Evidence integrity
Orbit does not claim immutable evidence. The current safe maturity statement is: timestamped evidence records with source references. Append-only behavior, versioned evidence history, cryptographic tamper evidence or external anchoring are not implemented in this repository.
Vulnerability disclosure
A verified security contact mailbox is not documented in this repository. Until that is finalized, do not publish invented addresses such as security@lucnox.com or privacy@lucnox.com.
Planned disclosure guidance: include affected URL, reproduction steps, impact, screenshots or logs without secrets, and your preferred contact method. Do not access, modify, delete or disclose data that does not belong to you. No bug-bounty payment, response time or safe-harbor term is promised until formally approved.
Compliance guardrail
Orbit provides technical discovery, governance signals and evidence workflows. It does not provide legal advice, certification or a complete determination of compliance with NIS2, the EU AI Act or other laws.
Microsoft scope