Security

Security architecture built for confidential workflows

High-trust controls for secure participation, controlled access, and auditable collaboration.

Identity & access

Verified account onboarding, secure authentication, multi-factor support, and controlled session management.

Role-based access

Organization and deal-level permissions enforced at the application and data layers. Tenant context is required for all workspace operations.

Audit trails

Immutable logging of sensitive actions and account events, queryable by organization administrators.

Secure document sharing

Time-limited, revocable download links with tenant-scoped object storage and permission checks on every request.

Authentication & session security

  • Credential handling - Passwords are securely hashed and plaintext credentials are never stored or logged.
  • Session model - Access uses secure session controls with protected storage and revocation support.
  • Multi-factor authentication - MFA is available for all accounts and can be enabled in Profile & Security settings.
  • Password recovery - Self-service reset uses secure, single-use email links and generic responses that avoid account enumeration.
  • Session control - Users can review active sessions and revoke them from settings. Password changes invalidate existing sessions.

Abuse protection

  • Rate limiting on authentication, password recovery, and sensitive API endpoints.
  • Resend and recovery throttling to prevent spam and brute-force abuse patterns.
  • Account enumeration resistance - login and recovery flows return generic responses that do not confirm account existence.

Data protection

  • Tenant isolation - All workspace records carry organization scope enforced by database query filters.
  • Field-level encryption - Sensitive profile and deal metadata is encrypted at rest.
  • PII handling - Email addresses and names are masked in audit metadata and outbound notifications where appropriate.
  • Client protection - Security-sensitive session artifacts are kept out of JavaScript-accessible application state.

Infrastructure

Monitored systems, health-checked dependencies, structured logging with sensitive data redaction, and secure object storage for document artifacts. All API traffic is served over HTTPS with security headers applied at the edge.

Review our security posture with your team

Contact security
An error has occurred. This application may no longer respond until reloaded. Reload 🗙

Restoring your secure session

Reconnecting to the Luxminex workspace. This usually takes a moment.

Connection interrupted

Retrying in s. Attempt of .

Unable to reach the server

The secure channel could not be restored. Check that services are running, then retry or reload the page.