SECURITY

Security built around a local data boundary.

LUNAZET reduces cloud exposure by keeping prospect and outreach data local. No software can make an absolute security guarantee.

POSTUREDesign documented

Independent review pending

Development security statement — controls require independent review and release testing.

BOUNDARY 01

On your device

Working data is intended to remain in local SQLite, with mailbox secrets protected by Electron safeStorage outside the database.

  • Mailbox secrets are encrypted with Electron safeStorage; SQLite retains opaque references only.
  • Scanner targets and redirects are checked against private and reserved network ranges.

BOUNDARY 02

In the account service

The current web schema holds account, plan, billing, licence, Stripe-reference, processed-event, and device state.

  • Account identity
  • Plan, billing, and licence state
  • Stripe customer and subscription references
  • Processed Stripe event identifiers
  • Device activation records

BOUNDARY 03

Defensive controls

Scanner, desktop, account, and provider edges use narrow validated boundaries.

  • Approvals bind message, recipient, sender, evidence, offer, and schedule hashes.
  • Audit events form a tamper-evident local hash chain.

RESPONSIBLE REPORTING

Report a security concern

The dedicated reporting channel opens before public binaries ship. During private preview, use the waitlist to stay informed. Do not submit credentials or personal prospect data.

Follow the private preview