Official Meta integrations
WhatsApp Business, Instagram, and Messenger via official APIs—no scraping or unofficial clients.
Trust Center
Last updated: May 2026
Security is built into our product—not bolted on. This page summarizes the controls we operate today. We align with enterprise expectations for Meta messaging platforms while being transparent about our maturity path toward formal certifications.
WhatsApp Business, Instagram, and Messenger via official APIs—no scraping or unofficial clients.
HMAC-SHA256 signature validation with timing-safe comparison on inbound Meta events.
Integration tokens and secrets encrypted at rest (AES-256-GCM). Secrets never returned in browser API responses.
Every data path scoped by business_id in application code, with automated cross-tenant denial tests in CI.
Role-based team permissions, session rotation on login, HttpOnly cookies, and Origin checks on mutating requests.
API and webhook rate limits, burst protection, plan quotas, and human escalation workflows.
| Threat | Mitigation |
|---|---|
| Webhook forgery | Meta HMAC-SHA256 (x-hub-signature-256), timing-safe compare |
| Replay / duplicate delivery | External message idempotency on inbound messages |
| Credential theft | Encryption at rest; redacted API responses; no secrets in logs |
| Cross-tenant access | business_id scoping + automated isolation tests |
| Spam / flood | Rate limits, burst limiter, plan quotas |
| Session hijack | HttpOnly cookies, hashed session tokens, rotation on login |
| Supply-chain risk | Dependabot, npm audit in CI, lockfile enforcement |
Our database uses Supabase with a service-role backend. Row-level security is not the primary isolation boundary—application-layer enforcement on every repository call is.
Automated security tests in continuous integration verify that one tenant cannot access another tenant’s resources by identifier guessing.
Report vulnerabilities privately to support@lumorq.com. Please include steps to reproduce and impact assessment.
We aim to acknowledge reports within 3 business days and provide a remediation timeline for confirmed issues.
Please do not access data belonging to other customers or disrupt production systems.
When self-serve billing is enabled, subscription payments are processed by Stripe using Stripe Checkout. Card numbers are entered on Stripe-hosted pages and are not stored on our servers.
Merchants using Stripe Checkout typically qualify for PCI SAQ A scope. You remain responsible for securing your account credentials and workspace access.
See our Privacy Policy for full subprocessor detail and data-processing context.