Security

Zero-trust by default. Verizon-grade by design.

Luxara Connect OS treats every carrier call, every credential, and every privileged action as sensitive. Approvals are workflow-gated, secrets stay server-side, and every event is logged.

SOC 2 Type II (in progress)GDPR alignedCCPA alignedTLS 1.3AES-256 at restZero-trust ready

Zero-trust path

Every privileged action passes through five gates.

01

Session

MFA + device fingerprint

02

Role

RBAC + tenant scope

03

Policy

Approval matrix check

04

Action

Server-side carrier call

05

Audit

Immutable log write

Safeguards

Nine pillars, built in from day one.

Server-side credentials

ThingSpace keys are vaulted server-side. The browser never sees a secret.

Approval workflows

Suspend / restore / reassign require admin sign-off with reason capture.

Audit on every call

Every sensitive action is attributed, timestamped, and immutable.

RBAC + MFA

13 default roles, granular permission set, MFA enforced for privileged users.

Billing isolation

Stripe webhooks update billing state only — never trigger carrier actions.

Multi-tenant by design

Organization isolation enforced at the data layer with RLS.

Zero-trust mode

Every privileged action re-verifies session + role + tenant scope.

Compliance-ready logging

Exportable audit trails with risk classification (Low → Critical).

Credential vault access

Vault access is itself audited; support cannot read raw secrets.

What we never store

  • Plain-text Verizon ThingSpace secrets
  • Plain-text payment card data (Stripe-tokenized)
  • Customer biometrics or government IDs
  • Unredacted carrier traffic content

Carrier safety rule

Failed payments never directly trigger Verizon suspension. Luxara creates billing alerts, applies grace periods, and queues suspend / restore actions that require admin approval before any server-side ThingSpace call executes.

Reviewing for procurement?

We provide architecture diagrams, audit samples, and security questionnaires on request.