Protect your account
Lomus supports password-based and connected-provider sign-in, session management, and available multifactor and passkey controls. Sensitive account actions can require additional verification. Use a unique password, enable available protections, and revoke sessions you do not recognise.
Workspace permissions
Invite team members into a shared workspace and assign owner, admin, member, or operator roles. These roles control administrative actions and access to resources. Backend requests check authentication and workspace access. Studio conversations are owned by their creator, rather than automatically visible to every workspace member. Grant only the access each person needs.
Agent boundaries and credentials
Agents run in isolated containers with restricted runtime access. Lomus uses AWS-backed encrypted secret storage for configured credentials and passes them to the features that need them. These controls reduce risk; they are not a guarantee that an agent or third-party skill can never cause harm. Review credentials and enabled skills carefully.
Shared and private secrets
The workspace secrets vault stores values as encrypted SecureString parameters in AWS Systems Manager Parameter Store, protected with AWS KMS. The database stores metadata, not the secret value. After saving, management views show the name, scope, and usage information rather than revealing the value again.
Shared secrets are available for authorised use in the workspace. Private secrets belong to their owner; if private and shared secrets have the same name, the owner’s private value takes precedence for their requests. Agents retrieve values through an authorised runtime request. A missing or unverified user identity cannot grant private access.
Studio supplies the signed-in user’s identity. Private access through Telegram and Discord requires linking the channel identity using the account-linking flow in Secrets. Private-secret identity linking is not currently provided for Slack. Use care when enabling skills: a tool authorised to use a credential still needs that value to perform its task.
Skills and connected services
The curated skill catalog is selected for the hosted environment, and custom skills go through a safety-review flow. Check each skill’s requirements and avoid granting unnecessary permissions. Third-party services have their own controls, availability, and data practices.
What we do not promise
No SOC 2 certification, HIPAA/BAA coverage, enterprise SSO, custom data residency, or uptime SLA is included as a general launch commitment. Discuss specific requirements with us before using Lomus for a regulated or specialised workload.
Report a security concern
Email support@lomus.ai with the subject “Security report”. Include the affected feature and safe reproduction steps. Do not access other users’ information, disrupt service, or post credentials or vulnerability details publicly. We will review your report; no fixed response-time guarantee or bounty is offered.