Security centre · Reviewed August 1, 2026

Your work deserves careful protection.

Security starts with clear boundaries. LumenQube keeps ordinary document editing local, protects the cloud features you choose to use, and explains the important limits without hiding them behind vague claims.

Local first

Your files stay on your device by default

Opening, editing, and saving local files does not silently upload their contents to LumenQube.

Encrypted

Protected in transit and at rest

Cloud requests use TLS. Shared content and connector secrets receive additional protection at rest.

Controlled

Access can be changed or revoked

Owners choose roles, can revoke links and members, and can rotate a shared document key after access changes.

Transparent

Cloud processing happens when you ask

AI, sharing, publishing, connectors, and submitted diagnostics are clearly identified cloud features.

Important: shared and published documents are encrypted at rest with server-managed keys; they are not end-to-end encrypted. LumenQube’s authorized server processes can decrypt the revision required to provide collaboration and web viewing. If your policy requires customer-held keys or end-to-end encryption, contact us before using those features.
Protection model

Security across the complete document journey.

Different features have different boundaries. These controls describe the current product design without implying a certification or guarantee.

Local files and device sessions

Local documents remain under your operating system account and device protections.

  • Desktop editing is local-first and does not background-upload document contents.
  • Signed-in session tokens use the operating system’s protected storage when available.
  • Sensitive Notes data and recordings can use OS-keychain-backed encryption at rest.
  • Autosave and recovery reduce the risk of work loss after an unexpected shutdown.

Accounts and authentication

Account controls are designed to resist common credential and session attacks.

  • Passwords are salted and hashed with scrypt; plain-text passwords are not stored.
  • Email verification and short-lived reset codes protect account recovery.
  • Access and refresh tokens are signed, expire, and support session or account-wide revocation.
  • Rate limits and account protections help deter brute-force and email-abuse attempts.

Sharing and publishing

Owners decide who can reach a cloud copy and what they may do with it.

  • Shared revisions are encrypted at the application layer and by the hosting platform at rest.
  • Viewer, commenter, and editor roles constrain collaboration access.
  • Public or restricted links can be revoked; optional passcodes are stored as hashes.
  • Server-side authorization is checked before an encrypted revision is opened for a viewer.

Connectors and external services

Connected accounts are optional and scoped to the action you authorize.

  • OAuth tokens are encrypted at rest with authenticated AES-256-GCM envelopes.
  • Connector credentials stay behind the server proxy rather than inside shared documents.
  • Disconnecting a provider removes LumenQube’s stored authorization for that connection.
  • Third-party services remain governed by their own security and privacy terms.

PDF privacy tools

Security-sensitive PDF actions are designed to change the underlying file, not only its appearance.

  • Secure redaction removes matched content and can sanitize hidden carriers and metadata.
  • Password protection and certificate signatures are available for supported workflows.
  • Sanitization can remove metadata, embedded files, scripts, hidden layers, form values, and other hidden content.
  • Users should still verify a finished redacted file before distribution.

AI processing

Only content needed for the AI action is sent through the managed backend to the selected provider.

  • LumenQube uses commercial/API offerings whose inputs and outputs are not used for model training by default.
  • Providers may retain limited request data for abuse monitoring or required application state.
  • AI output can be inaccurate; review results before relying on them.
  • Do not submit content you are not authorized to share with a processor.

Need the data-flow details? The Privacy Policy explains collection, subprocessors, retention, international transfers, and your rights.

Read the Privacy Policy →
Memory & context

What the workspace knows, and where each part of it is kept.

The assistant draws on two separate stores with different locations and different lifecycles. They are described here one at a time, because the honest answer differs per store and a single tier label would flatten it. The controls are in Settings → Memory & context.

The context graph

Links between your own notes, tasks, meetings, events and people, drawn from what is already on this computer.

  • This device only. A local database beside your documents; it is not synced to LumenQube and not backed up to us.
  • Nothing is fetched to build it — it is derived from files you already have.
  • Notes and tasks are held as sensitive and stay out of the plaintext index entirely.
  • The engine can be switched off, after which no context is assembled at all.

Durable memory

Facts the assistant saved because you told it something durable.

  • Two stores, not one synced store. Up to 200 are kept on this computer; the mobile app reads a separate cloud set of up to 64. The two do not reconcile, so they can genuinely differ.
  • Credentials, API keys, card numbers, private keys and recovery phrases are screened out before anything is saved or synced.
  • Switching memory off means the block is not built for a request at all.

What travels with a question

Two blocks, both readable in full before anything is sent.

  • The context pack carries titles and how far apart things are — never file contents, and is bounded at 24 items and 4,000 characters.
  • Objects you have excluded are removed before the pack is built, and are counted rather than silently dropped.
  • An object encrypted to a keychain this machine does not hold cannot be read into the pack.
  • The memory block rides the cached portion of the request rather than being re-sent per question.

Erasure

Forget reaches five stores, and no cascade spans them, which is why it is a deliberate operation rather than a delete.

  • The object, its links, the full-text index, the embeddings held in the app’s working memory, and any durable memory naming it.
  • The full-text index and the embeddings are each reached explicitly — a database cascade reaches neither.
  • Every store is attempted independently, and the result names what it could not reach instead of reporting success.
  • It does not reach copies you exported elsewhere, or a request already sent in an earlier conversation.

Want to see the exact text? The homepage prints both blocks verbatim, as the app assembles them.

See what gets sent →
Assurance & transparency

CSA self-assessments, published with the gaps left visible.

LumenQube has been listed in the CSA STAR Registry since July 31, 2026, carrying both STAR Level 1 and STAR for AI Level 1. Level 1 is a provider self-assessment that CSA publishes — it is not an independent audit or a third-party certification.

CSA STAR Level One: Self-Assessment — Security, Trust, Assurance and Risk CSA STAR for AI Level 1: Self-Assessment — Security, Trust, Assurance and Risk

Every answer we filed is public on our registry entry — 603 questions across CSA's Cloud Controls Matrix and AI Controls Matrix, including the ones still open. Read the entry →

Listed · July 31, 2026

CSA STAR Level 1

CAIQ v4.1 covers 283 cloud-security questions across the Cloud Controls Matrix. The published assessment identifies LumenQube, customer, and upstream-provider responsibilities and records open controls as open.

Listed · July 31, 2026

STAR for AI Level 1

AI-CAIQ v1.1 covers 320 responsible-AI and AI-security questions. LumenQube is assessed as an application provider that uses managed model APIs and does not train a foundation model on customer content.

Self-assessment

What Level 1 means

Level 1 is a public provider self-assessment. It is not a penetration test, independent audit, or guarantee, and the workbooks include truthful No and not applicable answers.

Review cadence

Kept current, not filed and forgotten

Both assessments are reviewed at least annually against the published registry date, and again after any material service, provider, legal, or threat-model change.

Need the assessment package? Contact us for the current version, scope, customer responsibilities, or a specific enterprise requirement.

Request the package →
Responsible disclosure

Found a security issue? Please tell us privately.

Email security@lumenqube.com with the affected product or URL, reproduction steps, impact, and any supporting evidence. Do not access other people’s data, disrupt service, use social engineering, or publicly disclose an unresolved issue. We will acknowledge the report and coordinate a responsible resolution in good faith.

Questions

Security, in plain language.

Are shared documents end-to-end encrypted?

No. Shared and published documents are encrypted in transit and at rest, including application-layer encryption for stored revisions, but LumenQube manages the keys so authorized server processes can render and synchronize the content. This is not end-to-end encryption.

When does a document leave my device?

Only when you choose a feature that needs cloud processing, such as AI, sharing, web publishing, a connected service, or a support report with attachments. Ordinary local editing does not silently upload document contents.

What is your CSA STAR status?

LumenQube is listed in the CSA STAR Registry and has been since July 31, 2026, carrying STAR Level 1 (CAIQ v4.1) and STAR for AI Level 1 (AI-CAIQ v1.1). Level 1 is a provider self-assessment that CSA publishes — it is not an independent audit, a third-party certification, or a penetration test. Every answer we filed is readable on the registry entry.

Can I revoke access to shared work?

Yes. Owners can change member roles, remove collaborators, revoke browser links, and rotate the document key after access changes. Copies that someone already downloaded remain outside LumenQube’s control.

Where can I make a privacy request?

Email privacy@lumenqube.com from your account address. The Privacy Policy explains access, correction, deletion, portability, objection, and restriction rights that may apply.

Make an informed product decision.

Review the complete data-flow policy, then see how LumenQube turns local files into editable outcomes.

Read the Privacy PolicyCollection, retention, subprocessors, and your rights.Review data flows → See LumenQube in actionWatch clearly labelled simulated product workflows.Open walkthroughs →