Legal

Trust Center

The controls Lux operates against, how they are audited, and how to reach the security team.

Effective 2026-08-10 · Lux Industries Inc

Draft — not yet in force. This policy is published for review. It states how the network operates and what we intend to commit to, and it has not completed legal review. It does not yet form part of any agreement.

  1. 01

    Programme

    Lux operates an information security programme covering the network, the control plane and the facilities, with annual independent assessment and continuous internal control monitoring.

    Certification and attestation reports are available to customers and prospective customers under NDA, on request to the security team.

  2. 02

    Architecture

    Traffic is carried on the Lux backbone rather than the public internet wherever both endpoints are on the network, including orbital sites, which join the backbone at the ground station.

    Media, storage and inference are pinned per region. The region is recorded with the data and is verifiable in the console.

    Access to production is role-based, time-bound and logged. Privileged actions are individually attributable.

  3. 03

    Vulnerability reporting

    Report a vulnerability to the security address below. Lux acknowledges within one business day, provides an assessment within five, and does not pursue researchers who act in good faith and within the scope published in the security policy.

  4. 04

    Incidents

    Security incidents affecting customer data are notified to affected customers without undue delay and within the periods the applicable law requires, with the facts known at the time and updates as the investigation proceeds.

Questions about this policy go to [email protected]. Privacy requests go to [email protected], and legal process is served on [email protected].