Meet Lula

Security and data

Keep client work separated, traceable and controlled.

Lula coordinates brand information, campaign drafts, contacts, sending activity and results, which makes clear data boundaries essential. Security is an ongoing operational responsibility, so this page explains the principles Lula applies without claiming certifications or controls that have not been independently verified.

Client workspace separation

Private client work stays with the client.

Separate records

Briefs, spokespeople, evidence, drafts, campaigns, approvals and results are assigned to the correct workspace.

Scoped access

Users only see the accounts and functions their role permits.

Sender assignment

Domains and sender identities remain connected to the correct account and campaign.

Administrative access

Authorised operators may access accounts for support, quality and troubleshooting, handled carefully and recorded.

Shared operational data

Coordinate safety without sharing strategy.

Opportunity sources

A public or licensed request is ingested once and matched separately for eligible brands.

Contact health

Hard bounces, availability holds and applicable global restrictions can protect more than one campaign.

Conflict checks

Recent campaign activity can prevent inappropriate simultaneous approaches.

Isolation remains

One brand's score, angle, draft, approval, strategy and performance are never exposed to another.

Access and authentication

Protect both customer and administrative surfaces.

Account access

Authenticated sessions and role-based permissions apply to customer and administrative areas.

Admin controls

High-impact support actions, including account impersonation, are limited to authorised staff and auditable.

Secrets

API credentials and service secrets stay in protected server-side configuration.

Least privilege

Integrations receive only the access their workflow requires.

Revocation

Compromised credentials, users, senders and integrations can be removed or paused.

Data integrity and auditability

Know which information produced an action.

Source provenance

Where an opportunity, contact or fact came from is recorded.

Approval history

Each external action is connected with the decision or rule that allowed it.

Change history

Material updates to briefs, campaigns and restrictions stay traceable.

Outcome records

Replies, placements and citations link back to the relevant campaign and source.

Error handling

Failed jobs are visible, retryable where safe, and prevented from silently duplicating external actions.

Third-party services

Integrations have their own responsibilities.

Data providers

Opportunity and contact services may supply licensed records under their own terms.

Sending and domain services

Infrastructure providers process the information required to register, configure and send.

Billing

Payment providers handle payment information under their own security and privacy practices.

Customer visibility

Material subprocessors and data terms will be documented as the product reaches general availability.

Frequently asked questions

Is client data shared with other customers?
No. Private briefs, drafts, approvals, strategy and performance remain isolated. Shared operational signals are limited to platform coordination and safety.
Can administrators access my account?
Authorised access may be required for support and quality. It is restricted, recorded and handled transparently.
Are API keys stored in the browser?
No. Sensitive service credentials remain in protected server-side configuration.
Does Lula claim a security certification?
No certification is claimed on this page.
What happens after a hard bounce?
The invalid address is restricted centrally to prevent repeated failed sends.
Where can I ask a security question?
Use the contact page and identify the request as a security or data enquiry.