Technical and organizational measures
Lutin uses technical and organizational measures (TOMs) designed to protect the confidentiality, integrity, and availability of personal data. This page is a plain-language overview of our current security boundary, not a certification or a guarantee that every risk can be eliminated.
Data protection
- Data is protected in transit with TLS.
- Cloud account databases use provider-managed encryption at rest.
- Local data benefits from the operating system's file protections, including iOS Data Protection on supported Apple devices.
Lutin does not currently claim end-to-end or zero-knowledge encryption. The local database is not encrypted as a whole, and authorized Lutin runtimes and authorized infrastructure operators may be able to read cloud account data.
Access and account isolation
- Each account has its own account database and cloud runtime boundary.
- Trusted runtimes receive short-lived database credentials scoped to one account.
- Cloud runtimes do not receive database-platform credentials or credentials for another account.
- Authentication, account isolation, and execution controls are checked separately from database access.
Credential handling
Session tokens, connector credentials, provider API keys, push tokens, and infrastructure credentials are kept out of the synchronized account database. Device-held secrets are stored in the operating system keychain. Server-held connector and push credentials are encrypted with service-managed keys, while credentials that only need verification may be stored as hashes.
Operational safeguards
Our cloud service boundaries are designed to keep private account content out of infrastructure logs, metrics, notifications, and service names. Application diagnostics may include user-provided titles, URLs, or error details. We review this security boundary as the product changes and avoid making stronger privacy claims until the supporting controls have been implemented and reviewed.
Privacy
Our Privacy Policy explains what information we collect, why we process it, how long we retain it, and the rights available to you. Our Subprocessors page lists the providers that may process data on our behalf. Questions about your data can be sent to [email protected].
Report a security issue
If you believe you have found a vulnerability, email [email protected]. Please include the affected URL or app version, reproduction steps, and the potential impact. Do not include unnecessary personal data or publicly disclose the issue before we have had a reasonable opportunity to investigate it.
Automated security contact details are available in our security.txt file.







