Security and data
Keep client work separated, traceable and controlled.
Lula coordinates brand information, campaign drafts, contacts, sending activity and results, which makes clear data boundaries essential. Security is an ongoing operational responsibility, so this page explains the principles Lula applies without claiming certifications or controls that have not been independently verified.
Client workspace separation
Private client work stays with the client.
Separate records
Briefs, spokespeople, evidence, drafts, campaigns, approvals and results are assigned to the correct workspace.
Scoped access
Users only see the accounts and functions their role permits.
Sender assignment
Domains and sender identities remain connected to the correct account and campaign.
Administrative access
Authorised operators may access accounts for support, quality and troubleshooting, handled carefully and recorded.
Shared operational data
Coordinate safety without sharing strategy.
Opportunity sources
A public or licensed request is ingested once and matched separately for eligible brands.
Contact health
Hard bounces, availability holds and applicable global restrictions can protect more than one campaign.
Conflict checks
Recent campaign activity can prevent inappropriate simultaneous approaches.
Isolation remains
One brand's score, angle, draft, approval, strategy and performance are never exposed to another.
Access and authentication
Protect both customer and administrative surfaces.
Account access
Authenticated sessions and role-based permissions apply to customer and administrative areas.
Admin controls
High-impact support actions, including account impersonation, are limited to authorised staff and auditable.
Secrets
API credentials and service secrets stay in protected server-side configuration.
Least privilege
Integrations receive only the access their workflow requires.
Revocation
Compromised credentials, users, senders and integrations can be removed or paused.
Data integrity and auditability
Know which information produced an action.
Source provenance
Where an opportunity, contact or fact came from is recorded.
Approval history
Each external action is connected with the decision or rule that allowed it.
Change history
Material updates to briefs, campaigns and restrictions stay traceable.
Outcome records
Replies, placements and citations link back to the relevant campaign and source.
Error handling
Failed jobs are visible, retryable where safe, and prevented from silently duplicating external actions.
Third-party services
Integrations have their own responsibilities.
Data providers
Opportunity and contact services may supply licensed records under their own terms.
Sending and domain services
Infrastructure providers process the information required to register, configure and send.
Billing
Payment providers handle payment information under their own security and privacy practices.
Customer visibility
Material subprocessors and data terms will be documented as the product reaches general availability.
Frequently asked questions
- Is client data shared with other customers?
- No. Private briefs, drafts, approvals, strategy and performance remain isolated. Shared operational signals are limited to platform coordination and safety.
- Can administrators access my account?
- Authorised access may be required for support and quality. It is restricted, recorded and handled transparently.
- Are API keys stored in the browser?
- No. Sensitive service credentials remain in protected server-side configuration.
- Does Lula claim a security certification?
- No certification is claimed on this page.
- What happens after a hard bounce?
- The invalid address is restricted centrally to prevent repeated failed sends.
- Where can I ask a security question?
- Use the contact page and identify the request as a security or data enquiry.
