A LITTLE PEACE OF MIND

Built with care. Managed with context.

Practical protections for your account, workspace, and agents—with clear limits.

Last updated: 6 September 2026

Protect your account

Lomus supports password-based and connected-provider sign-in, session management, and available multifactor and passkey controls. Sensitive account actions can require additional verification. Use a unique password, enable available protections, and revoke sessions you do not recognise.

Workspace permissions

Invite team members into a shared workspace and assign owner, admin, member, or operator roles. These roles control administrative actions and access to resources. Backend requests check authentication and workspace access. Studio conversations are owned by their creator, rather than automatically visible to every workspace member. Grant only the access each person needs.

Agent boundaries and credentials

Agents run in isolated containers with restricted runtime access. Lomus uses AWS-backed encrypted secret storage for configured credentials and passes them to the features that need them. These controls reduce risk; they are not a guarantee that an agent or third-party skill can never cause harm. Review credentials and enabled skills carefully.

Shared and private secrets

The workspace secrets vault stores values as encrypted SecureString parameters in AWS Systems Manager Parameter Store, protected with AWS KMS. The database stores metadata, not the secret value. After saving, management views show the name, scope, and usage information rather than revealing the value again.

Shared secrets are available for authorised use in the workspace. Private secrets belong to their owner; if private and shared secrets have the same name, the owner’s private value takes precedence for their requests. Agents retrieve values through an authorised runtime request. A missing or unverified user identity cannot grant private access.

Studio supplies the signed-in user’s identity. Private access through Telegram and Discord requires linking the channel identity using the account-linking flow in Secrets. Private-secret identity linking is not currently provided for Slack. Use care when enabling skills: a tool authorised to use a credential still needs that value to perform its task.

Skills and connected services

The curated skill catalog is selected for the hosted environment, and custom skills go through a safety-review flow. Check each skill’s requirements and avoid granting unnecessary permissions. Third-party services have their own controls, availability, and data practices.

What we do not promise

No SOC 2 certification, HIPAA/BAA coverage, enterprise SSO, custom data residency, or uptime SLA is included as a general launch commitment. Discuss specific requirements with us before using Lomus for a regulated or specialised workload.

Report a security concern

Email support@lomus.ai with the subject “Security report”. Include the affected feature and safe reproduction steps. Do not access other users’ information, disrupt service, or post credentials or vulnerability details publicly. We will review your report; no fixed response-time guarantee or bounty is offered.