LúminaKite

Plans, capabilities, and limits

Document: LK-MAN-EN-04 · Version: 0.1
Last updated: 2026-07-18 · Status: draft / requires commercial and product review
Audience: owners, procurement, security, and operations

This table reflects product defaults on the stated date; it does not replace a quote or contract. Temporary overrides can change an organization's result.

Contents

  1. Reading the table
  2. Capability matrix
  3. Limit matrix
  4. Enforcement and overrides
  5. Operational selection

<a id="reading-the-table"></a>

1. Reading the table

  • ✓: enabled by default.
  • —: not enabled by default.
  • Pro+: available on Pro and Business.
  • Two internal backward-compatibility keys for Brand Protection represent one visible capability.
  • The UI may hide, lock, or show an upgrade notice; the backend also enforces capability and limit.
  • Check Billing for the active organization's effective entitlements.

<a id="capability-matrix"></a>

2. Capability matrix

CapabilityFreeProBusinessNote
Basic DNS and emailEssential posture
ASM NormalCadence by plan
Basic uptimeMonitors and retention are limited
Security casesRemediation traceability
Unified finding alertsOperational inbox
Risk scoreAggregate prioritization
WebhooksSubject to plan maximum
Quiet hoursAlert policy
Advanced alertingExpanded rules
Advanced TLS postureAdvanced assessment
CT auto-discoveryCertificate Transparency
Multi-organizationMultiple account contexts
Identity LeaksRestricted handling required
Full DNS and emailExpanded assessment
Multi-region uptimeRegional coverage and consensus
Uptime status pagesControlled publication
ReportsExecutive/technical and PDF
Brand ProtectionBrand and impersonation
API accessScoped keys
DMARC RUA ingest/inboundAggregate reports
DMARC assistantGuided workflow
ASM PlusGreater depth and concurrency

<a id="limit-matrix"></a>

3. Limit matrix

Per-organization limitFreeProBusiness
Maximum domains250200
Maximum verified domains125200
General retention14 days90 days180 days
TLS check interval720 min60 min15 min
Alert channels1520
Webhooks0520
Expiry thresholds357
Minimum deduplication60 min30 min15 min
DNS/email interval1,440 min360 min60 min
ASM Normal interval1,440 min720 min180 min
ASM Plus intervalNot applicableNot applicable180 min
ASM Plus concurrency0020
ASM Plus rate limit00300/min
Uptime monitors250200
Minimum uptime interval900 s300 s60 s
Uptime retention7 days30 days90 days
Uptime timeout5,000 ms10,000 ms15,000 ms
Uptime regions135
Status pages0110

Limits are organization-level and may interact. For example, having uptime enabled does not prevent a creation request from being rejected after reaching max_uptime_monitors.

<a id="enforcement-and-overrides"></a>

4. Enforcement and overrides

The service resolves effective entitlement using:

  1. the plan assigned to the organization;
  2. baseline feature flags and limits;
  3. applicable, unexpired capability or limit overrides;
  4. current consumption;
  5. role and resource authorization.

Results can be cached for up to five minutes. After a commercial change or override, wait for refresh or follow the operations invalidation procedure.

An override must not bypass authorization, multi-tenant isolation, or security controls. Record owner, justification, value, and expiry.

<a id="operational-selection"></a>

5. Operational selection

Main needMinimum-plan reference
Small inventory, basic posture, cases, and riskFree
More domains, reports, Identity Leaks, advanced TLS/DNS, multi-region, webhooksPro
API, Brand Protection, DMARC RUA/assistant, ASM Plus, and high limitsBusiness

Final selection should consider volume, frequency, retention, regions, integrations, and contractual obligations—not only the presence of one feature.


Change control: v0.1 — initial matrix based on product defaults, 2026-07-18.