This article covers where each kind of credential is stored, how it is encrypted, and the rules governing how LuumenAI uses it.
Where Credentials Are Stored
Storage depends on the option you choose when you create the credential.
Option | Where the Secret is | Shareable |
Local SSH Keychain | On your computer, in your SSH agent or | No. Personal scope only. |
Password with Storage Local | On this machine only. | No. |
Password with Storage Luumen Cloud | In your workspace, encrypted. | Yes, as a workspace credential on Team and Enterprise. |
Upload Private Key | In your workspace, encrypted. | Yes, as a workspace credential on Team and Enterprise. |
How Credentials Are Protected
Encrypted at rest. Passwords and private keys are encrypted with AES-256-GCM before they are written to storage. They are never stored as plain text.
Encrypted in transit. All traffic between the app and our servers uses TLS.
Write-only. Once saved, a secret cannot be read back out through the app or the API by anyone, including you. You can replace a secret, never view it.
Decrypted only for use. A credential is decrypted to open a connection you asked for, and held only as long as that takes.
Scoped where you put them. A personal credential is visible to you alone. A workspace credential is visible only to members of that workspace. Your credentials are never visible across organizations.
For more information please see: security.
How LuumenAI Uses Credentials
LuumenAI has no access of its own. It does not hold credentials and cannot authenticate to anything. When it runs a command, it runs inside the session you opened, using the credential you chose, with your permissions on that host. It cannot reach a server you could not reach yourself, and it cannot escalate beyond the account you connected as.
Every command is approved by you. There is no standing permission and no category of command that runs unattended.
Secrets are not sent to the model. LuumenAI works with the state of the host and the output of commands you approve, not with the credential used to reach it.
Managing and Removing Credentials
Delete any credential at any time. Deletion is blocked only while hosts still depend on it, so you are told what will break before anything does. Rotate a shared secret by editing the credential once; every host using it picks up the change at its next connection.
On Enterprise, credential changes and every connection made with a credential are recorded in the audit log.

