Skip to main content

Document metadata

Status
Maintained
Approval
Approved
Version
1.0
Classification
PUBLIC
Owner
Lightning IT Documentation Maintainers
Approver
Lightning IT Security and Compliance Maintainers
Audience
customers, security reviewers
Last reviewed
Next review
(Semiannual)

Security and vulnerability handling

Policy. Security work follows least privilege, immutable-source traceability, input validation, secret separation, and scoped verification. The canonical public boundary is the security overview and publication boundary.

Documented process. Vulnerabilities are handled through restricted channels; only safe, authorized summaries are published. Findings, exploit paths, customer data, internal topology, risk acceptance, and incident detail remain protected.

Unverified gap — external security assessment. No current public external assessment is asserted for the complete portfolio. Owner: Security Owner. Review trigger: an authorized, current, scope-specific public report.