Security

Security and responsible disclosure

A verification service is only as trustworthy as its response to its own failures. This page explains how to report a vulnerability, what we commit to when you do, and what happens to Lumethic-signed credentials if our checks or keys are ever compromised.

Reporting

How to report a vulnerability

If you believe you have found a security issue in Lumethic — a way to make a forged image pass verification, a flaw in the platform, the API, the browser tools, or the apps — we want to hear about it before anyone else does.

  • Email hello@lumethic.com with "Security" in the subject line. A machine-readable version of this contact information is published at /.well-known/security.txt.
  • Include what you found, the steps to reproduce it, and, if the issue concerns the verification engine, the files involved. Please do not include anyone else's personal data.
  • We will acknowledge your report within three business days, keep you informed while we investigate, and tell you when the issue is fixed.
  • If you would like public credit once the issue is resolved, we will gladly name you. If you prefer to stay anonymous, we will respect that.

Good-faith research

What we ask, and what we promise

We will not take legal action against research conducted in good faith: testing against your own accounts and files, respecting other users' data and privacy, avoiding service disruption, and giving us reasonable time to fix an issue before disclosing it publicly.

Out of scope: denial-of-service and volumetric attacks, spam or social engineering of Lumethic users or staff, physical attacks, and vulnerabilities in third-party services we use but do not operate. Reports consisting only of automated scanner output without a demonstrated impact are unlikely to qualify for credit.

Attempts to defeat the verification engine itself — fabricated RAW files, recapture attacks, manipulated submissions — are explicitly in scope and are the reports we value most. Use your own images and report what you find rather than publishing a bypass.

Certificate governance

How Lumethic-signed credentials are governed

Lumethic signs C2PA manifests only for images that have passed forensic verification, using ECDSA P-384 signing keys that are managed separately from the application infrastructure and are never present in the browser or in client tools.

If a signing key is ever compromised, or a demonstrated bypass has caused content to be signed that should not have been, we commit to the following, in this order: revoke the affected certificate so that the affected manifests no longer validate in C2PA tools, publish an incident report stating what happened and which time window is affected, and notify affected account holders directly.

The industry has already seen what happens when this planning is missing: when a camera maker's signing process was bypassed in 2025, every certificate it had issued had to be revoked after the fact. A trust product must plan its own failure modes before they occur, and publishing this procedure in advance is part of that.

Incident response

How incidents are handled

Confirmed security incidents are triaged immediately: assess the scope, close the vulnerability, then disclose. Where an incident affects the validity of issued verification reports or signed credentials, the disclosure names the affected time window so that relying parties can re-check.

Personal data breaches are handled in line with Articles 33 and 34 of the GDPR, including notification of the supervisory authority within 72 hours where required and direct notification of affected users where the risk warrants it.

Found something?

Write to us before publishing. We read every report, and the ones that break our engine make the product better for everyone who relies on it.