Security
Security testing
Last updated · October 7, 2026
Automated static and dynamic analysis on a continuous cycle, independent penetration testing every quarter.
Security testing
| Programme | Status |
|---|---|
| Dynamic analysis (DAST) | Run weekly by a third-party platform against app.lutril.com in real attack conditions, with no prior knowledge of the application. Most recent run 5 October 2026. |
| Static analysis (SAST) | Security review of the application code with repository access. Most recent campaign 6 October 2026. |
| Independent penetration testing | Quarterly, blackbox and whitebox. Reports available under NDA on request to security@lutril.com. |
| Dependencies | Application dependencies and container images are scanned continuously. |
| Remediation targets | Critical 48 hours, high 7 days, medium 30 days, low 90 days, from the moment a finding is qualified. |
| Responsible disclosure | Contact published at security.txt. We acknowledge quickly and keep the reporter informed until the fix ships. |
- Changes are peer-reviewed and deployed through controlled, traced procedures.
- Containers run as an unprivileged user, and no service other than the reverse proxy publishes a port.
- Security headers are set on every response including errors: content security policy, HSTS, frame protection, MIME-sniffing protection and a referrer policy.
- Rate limiting applies at the edge on the authentication and authorisation endpoints, and inside the application everywhere else.
- The application's content security policy still allows inline and evaluated scripts, required by the current frontend bundle. Tightening it is tracked.