Security & Trust
Last updated: 2026-06-06
We build Lume so that your data is protected by sensible defaults, not by hoping nothing goes wrong. Here is concretely how we keep your account, your data and your payments safe — and what control you have over them.
Authentication
Accounts are protected by Supabase Auth. You can sign in with email and password, a 6-digit one-time code sent to your inbox, or Google OAuth. Sessions are kept in secure, HTTP-only cookies rather than in browser-readable storage, so a stray script cannot lift your session token.
Data isolation
Your data lives in Postgres with Row-Level Security enabled. Every row is scoped to its owner via auth.uid(), so the database itself enforces that you can only read and write your own projects, scans and reports — even if application code had a bug, the policy still blocks access to anyone else's rows.
Payments
Billing is handled end-to-end by Stripe (Checkout and the Customer Portal). Card numbers are entered on Stripe's own pages and never touch Lume's servers — we never see or store your full card number. Subscriptions and invoices are managed through Stripe's secure portal.
Transport security
Everything is served over HTTPS/TLS, with certificates from Let's Encrypt. Plain HTTP requests are redirected to HTTPS, so traffic between your browser and Lume is encrypted in transit.
Privacy by default
We do not run third-party tracking or advertising cookies today. The only cookies Lume sets are strictly necessary ones — your login session, your display language, and your light/dark theme preference. No ad networks, no cross-site profiling.
Hardening
User-supplied URLs (for example webhook endpoints) are validated to mitigate server-side request forgery (SSRF), so they cannot be abused to reach internal addresses. Authentication redirects are checked to prevent open-redirect abuse. We keep our dependencies patched and update promptly when security fixes are released.
Your control over your data
You stay in control. From your account page you can export your data with one click, and you can permanently delete your account — which removes your related data such as projects — whenever you choose.
Responsible disclosure
If you believe you have found a security issue, we want to hear from you. Please email security@lume-seo.com with the details and steps to reproduce. We commit to a good-faith response and to working with you to resolve valid reports. We do not currently offer a paid bug bounty, but we are grateful for responsible disclosure.