Security by Design
How security is built into LucentSkill from the ground up: the standards, frameworks, and engineering methods every feature is held to, and what they mean for your organization's data.
Security by Design
Security at LucentSkill is a design principle, not a bolt-on. Every feature, whether it touches authentication, AI generation, or the database, is built to recognized industry standards and ships only after it passes a security review. Controls live on the server, never only in the interface, and they fail closed: when something cannot be verified, access is denied rather than assumed safe.
- Fail closed by default: a missing secret, an invalid token, or an unexpected input denies access; it never widens it.
- Least privilege: three roles (owner, admin, member) are enforced on the server on every request, and a lower role can never act above its level.
- Tenant isolation: every query is scoped to the caller's organization, so one tenant's data can never be read or changed by another.
- Defense in depth: the authentication, session, and data layers each enforce their own checks, so no single layer is a single point of failure.
- No secrets in code or logs: keys are write-only and encrypted at rest, and credentials are never logged.
- Verified, not assumed: security controls are exercised end to end, including runtime checks that keys match and encrypted data round-trips.
Standards and frameworks
LucentSkill is built to recognized industry standards. Each one below maps to a concrete, documented part of the product.
- OWASP Application Security Verification Standard (ASVS) v4: the broadest current application-security checklist, applied across authentication (V2), session management (V3), access control (V4), cryptography (V6), logging (V7), and configuration (V14).
- OWASP Top 10 (Web): injection, broken access control, server-side request forgery, and the other top web risks are designed out and continuously re-checked.
- OWASP Top 10 for Large Language Models: prompt injection (LLM01) is defended with a two-layer classifier in front of every AI path, including learner grading.
- MITRE ATLAS: the adversary-tactics framework for AI systems, used to map and close the prompt-injection techniques a red team would try.
- NIST SP 800-63B: the digital-identity guideline that governs authenticator strength for multi-factor authentication.
- RFC 6238 (TOTP): the time-based one-time-password standard behind Google Authenticator, 1Password, and Authy.
- OAuth 2.0 (RFC 6749) with Proof Key for Code Exchange (RFC 7636) and OpenID Connect: the foundation of Microsoft Entra ID single sign-on.
- Microsoft Entra ID: identity federation that keeps each organization's directory and sign-in policy under its own tenant's control.
- PCI DSS Requirement 3.4: applied to protect stored member and contact data at rest, even though LucentSkill does not process payment card data.
- GDPR Articles 5 through 30: consent, transparency, the right to export, the right to erase, retention limits, and records of processing.
- WCAG 2.2 AA: every interface is kept accessible, so security controls are usable by everyone.
Engineering methods
- Proven cryptography, never hand-rolled: AES-256-GCM for data at rest, bcrypt for password hashing, and HMAC with scrypt for key derivation, with timing-safe comparisons throughout.
- Server-side authorization on every route: role checks are re-evaluated on each request, never cached or trusted from the browser.
- Step-up authentication: sensitive admin actions require a fresh multi-factor check, so a stolen session alone cannot change an organization.
- Append-only audit logging: security events are recorded immutably and cannot be edited or erased after the fact.
- Two-layer prompt-injection defense: a fast pattern layer on every input, plus a semantic classifier on suspicious inputs, with a safe fallback that never blocks a legitimate learner.
- Rate limiting and lockout: sign-in and multi-factor paths throttle repeated attempts and lock out brute force.
- Continuous security gating: static code analysis (CodeQL), dependency and secret scanning, and a type-checked build run on every change before it ships.
What it means for your organization
- Your identity stack stays yours: bring your own Microsoft Entra ID tenant and your own AI endpoint, so sign-in and generated data stay within the providers you choose.
- Your admins keep control: roles, multi-factor requirements, session revocation, and single sign-on are all managed from your administration console.
- Your data is protected at every stage: encrypted in transit and at rest, and guarded from prompt injection and cross-tenant access.
- You can hold it to the standard: every control is documented in this section, so your security team can review exactly how each is implemented and which standard it maps to.