Skip to content
All documentation

Security by Design

How security is built into LucentSkill from the ground up: the standards, frameworks, and engineering methods every feature is held to, and what they mean for your organization's data.

Security by Design

Security at LucentSkill is a design principle, not a bolt-on. Every feature, whether it touches authentication, AI generation, or the database, is built to recognized industry standards and ships only after it passes a security review. Controls live on the server, never only in the interface, and they fail closed: when something cannot be verified, access is denied rather than assumed safe.

  • Fail closed by default: a missing secret, an invalid token, or an unexpected input denies access; it never widens it.
  • Least privilege: three roles (owner, admin, member) are enforced on the server on every request, and a lower role can never act above its level.
  • Tenant isolation: every query is scoped to the caller's organization, so one tenant's data can never be read or changed by another.
  • Defense in depth: the authentication, session, and data layers each enforce their own checks, so no single layer is a single point of failure.
  • No secrets in code or logs: keys are write-only and encrypted at rest, and credentials are never logged.
  • Verified, not assumed: security controls are exercised end to end, including runtime checks that keys match and encrypted data round-trips.

Standards and frameworks

LucentSkill is built to recognized industry standards. Each one below maps to a concrete, documented part of the product.

  • OWASP Application Security Verification Standard (ASVS) v4: the broadest current application-security checklist, applied across authentication (V2), session management (V3), access control (V4), cryptography (V6), logging (V7), and configuration (V14).
  • OWASP Top 10 (Web): injection, broken access control, server-side request forgery, and the other top web risks are designed out and continuously re-checked.
  • OWASP Top 10 for Large Language Models: prompt injection (LLM01) is defended with a two-layer classifier in front of every AI path, including learner grading.
  • MITRE ATLAS: the adversary-tactics framework for AI systems, used to map and close the prompt-injection techniques a red team would try.
  • NIST SP 800-63B: the digital-identity guideline that governs authenticator strength for multi-factor authentication.
  • RFC 6238 (TOTP): the time-based one-time-password standard behind Google Authenticator, 1Password, and Authy.
  • OAuth 2.0 (RFC 6749) with Proof Key for Code Exchange (RFC 7636) and OpenID Connect: the foundation of Microsoft Entra ID single sign-on.
  • Microsoft Entra ID: identity federation that keeps each organization's directory and sign-in policy under its own tenant's control.
  • PCI DSS Requirement 3.4: applied to protect stored member and contact data at rest, even though LucentSkill does not process payment card data.
  • GDPR Articles 5 through 30: consent, transparency, the right to export, the right to erase, retention limits, and records of processing.
  • WCAG 2.2 AA: every interface is kept accessible, so security controls are usable by everyone.

Engineering methods

  • Proven cryptography, never hand-rolled: AES-256-GCM for data at rest, bcrypt for password hashing, and HMAC with scrypt for key derivation, with timing-safe comparisons throughout.
  • Server-side authorization on every route: role checks are re-evaluated on each request, never cached or trusted from the browser.
  • Step-up authentication: sensitive admin actions require a fresh multi-factor check, so a stolen session alone cannot change an organization.
  • Append-only audit logging: security events are recorded immutably and cannot be edited or erased after the fact.
  • Two-layer prompt-injection defense: a fast pattern layer on every input, plus a semantic classifier on suspicious inputs, with a safe fallback that never blocks a legitimate learner.
  • Rate limiting and lockout: sign-in and multi-factor paths throttle repeated attempts and lock out brute force.
  • Continuous security gating: static code analysis (CodeQL), dependency and secret scanning, and a type-checked build run on every change before it ships.

What it means for your organization

  • Your identity stack stays yours: bring your own Microsoft Entra ID tenant and your own AI endpoint, so sign-in and generated data stay within the providers you choose.
  • Your admins keep control: roles, multi-factor requirements, session revocation, and single sign-on are all managed from your administration console.
  • Your data is protected at every stage: encrypted in transit and at rest, and guarded from prompt injection and cross-tenant access.
  • You can hold it to the standard: every control is documented in this section, so your security team can review exactly how each is implemented and which standard it maps to.