Security is at the core of Lumos, and Lumos firmly believes in the power of working with security researchers to uncover weaknesses in our systems. Please reach out to us if you believe you’ve found a vulnerability in a Lumos service; we will work with you to resolve the issue promptly.
Authentication bypass or elevation of privileges
Sensitive data exposure
“Root” access to underlying servers
Multitenancy exploits
Please refrain from:
Denial of Service (DoS)
Spamming
Social engineering or phishing of Lumos employees

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we may take steps to make it known that your actions were conducted in compliance with this policy.
We want to hear from you! We can be reached at disclosure@lumos.com. Our PGP key is available here.
We may revise these guidelines from time to time. The most current version of the guidelines will be available at https://www.lumos.com/disclosure.
It is the Lumos Security team’s responsibility to enforce this policy.

Govern every human, machine, and AI in your business with a free identity assessment today.
Book a Demo