Reporting a vulnerability
Report privately through GitHub Security Advisories, or by email to security@lunos.tech. The process, from intake to disclosure, is in SECURITY.md.
Trust
For procurement and security reviewers: what Lunos does, what it doesn't, and where each statement is backed. Lunos holds no certification and claims none.
Documents
| Document | Covers | Status |
|---|---|---|
| Security overview | Architecture, trust boundaries, and a threat model: prompt injection, tool execution, supply chain, secrets, the audit log | Published. Each threat says what is mitigated and what is not |
| Supply chain | How releases are built, how to verify them, the SBOM, and marketplace review | Published. npm provenance, and Sigstore-signed checksums from v1.18.40; no OS code signing |
| EU Cyber Resilience Act | Scope assessment and readiness: SBOM, vulnerability handling, support periods | Published. Likely outside CRA scope; support periods not yet defined |
| Data protection (GDPR) | Controller and processor roles, data sent to model providers, a DPIA checklist | Published. Reviewed by counsel |
| Accessibility | EN 301 549 / WCAG 2.1 AA statement and conformance report | Not yet published. Audit in progress |
| CSA CAIQ v3.0.1 answers | Pre-filled answers to all 295 questions, with a spreadsheet copy | Published. Organisational questions are marked for ITService EOOD to answer |
Statements apply to the latest release, v1.18.40, unless marked "from the next release". The pack is versioned with the source; the authoritative copy is docs/trust in the repository.
Report privately through GitHub Security Advisories, or by email to security@lunos.tech. The process, from intake to disclosure, is in SECURITY.md.
Lunos is self-hosted: ITService EOOD runs no service in the data path and there is no telemetry. The full account is in the self-hosted deployment guide.