Document metadata
- Status
- Maintained
- Approval
- Approved
- Version
- 1.0
- Classification
- PUBLIC
- Owner
- Lightning IT Documentation Maintainers
- Approver
- Lightning IT Security and Compliance Maintainers
- Audience
- customers, security reviewers
- Last reviewed
- Next review
- (Semiannual)
Security and vulnerability handling
Policy. Security work follows least privilege, immutable-source traceability, input validation, secret separation, and scoped verification. The canonical public boundary is the security overview and publication boundary.
Documented process. Vulnerabilities are handled through restricted channels; only safe, authorized summaries are published. Findings, exploit paths, customer data, internal topology, risk acceptance, and incident detail remain protected.
Unverified gap — external security assessment. No current public external assessment is asserted for the complete portfolio. Owner: Security Owner. Review trigger: an authorized, current, scope-specific public report.