Security & Trust
Security at LUKUL
How Lukul Atelier LLC protects account, training, nutrition, coaching, and subscription information.
[ STATUS: SECURITY PROGRAM ACTIVE / CONTINUOUSLY IMPROVING ]
This page describes our current security approach. Only controls supported by current technical or operational evidence are represented as active.
Lukul Atelier LLC does not currently claim a SOC 2 attestation or ISO/IEC 27001 certification.
An evidence-led operating model
Lukul Atelier LLC maintains a documented, security-conscious operating model for account, training, nutrition, coaching, and subscription data.
Our approach includes controlled access boundaries, least-privilege application and database design, encrypted public web transport, version-controlled change controls, data-retention and deletion workflows, and a responsible reporting channel.
Security is an ongoing process. We review and improve our practices as the LUKUL platform, its integrations, and its user base evolve. Our controls and documentation are being organized to support transparency, customer due diligence, and potential future independent assurance.
01 / Principles
Security principles
Controlled access
Sensitive product paths are designed around authenticated identity, scoped roles, and explicit authorization boundaries.
Least privilege
Database roles, functions, and application services are granted only the permissions required for their defined responsibility.
Data lifecycle controls
Data access, retention review, export, and deletion are handled through documented product and support workflows appropriate to the data involved.
Continuous improvement
Security-sensitive changes are reviewed as the platform, integrations, and risk profile evolve. Public claims are narrowed when evidence is incomplete.
02 / Protection
How information is protected
Identity and access boundaries
The application codebase defines authenticated identity checks, role-scoped database permissions, row-level security boundaries, and server-side controls for sensitive data paths. Changes to those boundaries are version-controlled and covered by focused contract tests.
Data transmission
Lukul Atelier public web pages are delivered over HTTPS. Transport encryption protects data in transit between a browser and the supported web endpoint; it is not described here as end-to-end encryption.
Application change controls
Database and authorization changes are represented in version-controlled migrations. Focused automated tests check sensitive contracts including identity resolution, grants, row-level access, failure behavior, and migration ordering before release decisions are made.
Data minimization and retention
LUKUL aims to process information relevant to product operation, coaching workflows, security, support, and applicable obligations. Retention and deletion behavior depends on the data category; we do not promise immediate deletion from every system or retained backup.
Account deletion
Users can initiate account deletion through the published account-deletion workflow. Deletion or anonymization remains subject to legitimate legal, fraud-prevention, security, accounting, dispute, and backup-retention requirements.
03 / Assisted processing
AI-assisted processing
Certain LUKUL features may use automated or AI-assisted systems to generate performance insights, summaries, or coaching-support outputs. Feature-specific authorization and request boundaries limit what each supported workflow can process.
Provider handling can vary by feature and configuration. LUKUL therefore does not make a blanket public claim that every AI provider excludes submitted content from retention or model training.
AI-generated outputs are informational. They are not medical diagnoses and are not substitutes for qualified medical advice. See the Privacy Policy and Health Disclaimer for related boundaries.
04 / Assurance
Security and compliance status
| Framework or area | Current public status |
|---|---|
| SOC 2 | No SOC 2 report or attestation is currently claimed. |
| ISO/IEC 27001 | No ISO/IEC 27001 certification is currently claimed. |
| Payment-card handling | Complete payment-card details are not requested through LUKUL support channels. Provider-specific handling will be documented before a supported public purchase path opens. |
| Privacy | Current public practices are documented in the Privacy Policy and Account Deletion workflow. |
| Security program | Evidence-backed public claims, version-controlled security changes, and focused technical checks are maintained as the platform develops. |
| Future assurance | Independent assessment or certification may be pursued when customer requirements and operational scale justify it. |
SOC 2 addresses controls at a service organization through an independent assurance examination. ISO/IEC 27001 defines requirements for an information security management system. A cloud or service provider's assurance does not make Lukul Atelier LLC itself SOC 2 attested or ISO/IEC 27001 certified.
05 / Disclosure
Report a security concern
We welcome responsible reports of potential security issues affecting LUKUL services.
Send a clear description, affected URL or feature, reproduction steps, and any supporting evidence to bespoke@lukulatelier.com with Security report in the subject line.
Please do not access, modify, retain, or disclose data belonging to other users. Do not perform denial-of-service testing, automated high-volume scanning, social engineering, or actions that could disrupt service.
We aim to acknowledge credible reports within a reasonable period and prioritize them according to potential impact and available evidence. This policy does not promise payment, immunity, or a fixed response deadline.
Send a security report06 / Contact