Security at Lurk CFB
Last updated: September 9, 2026
Lurk CFB uses layered controls to protect customer accounts, organization data, connected services, and agent access. Security is part of how we design and operate the product.
Access and isolation
- Role-based access controls limit administrative and customer actions.
- Team entitlements scope customer workspaces, API credentials, agents, and connected channels.
- New customer accounts require approval before product access and billing begin.
- Agent tools and integrations are limited to the capabilities and teams assigned to the customer.
Data and integrations
- Application traffic uses encrypted HTTPS connections.
- Authentication and session handling use managed identity infrastructure and secure cookies.
- Connected-service tokens are encrypted before storage, and webhook signatures are verified where supported.
- Payment card details are handled by Stripe and are not stored by Lurk CFB.
Operations
We use service health checks, error monitoring, structured logs, dependency readiness checks, and database recovery features to detect and respond to operational problems. We review access and rotate credentials when required.
Report a security issue
Send a detailed report to info@lurkcfb.com. Please do not access, change, or retain data that does not belong to you while investigating an issue.