Transparency
Lunaris asks for permissions that could hurt you.Here is exactly what it does with them.
Handing Manage Roles, Kick Members, Ban Members, Manage Channels and View Audit Log to a developer you have never met is a real risk, and pretending otherwise would be the first thing worth distrusting. Below: every permission and what breaks without it, every field stored and for how long, and every place the product can be fooled. Read it before you install, not after something goes wrong.
Every permission, and what breaks without it.
Tap a card for why Lunaris asks and exactly what stops working if you refuse it. A permission with no consequence attached to its absence is a permission that was taken because it was easy to ask for.
Lunaris asks for Administrator. Here is what it actually uses.
A security bot that cannot reach a channel, a role or a webhook is a security bot with a blind spot, and a missing permission is the most common reason a protection silently does nothing during the attack it was installed for. Administrator closes that gap in one step. Every permission Lunaris actually exercises is listed below with what it does and what would break without it, so you can see exactly where that authority goes.
- Verification blocked
Manage Roles
Grants the verified role, strips attacker roles during a nuke.
Why we ask, and what breaks
Why we ask
Grants the verified role when a member passes, applies the quarantine role, and strips a rogue actor's roles while a nuke is in progress.
What breaks without it
Verification runs and then cannot let anyone in. Anti-nuke still detects the attack and still alerts, but it cannot take the attacker's roles away while it is happening.
- Manual removal only
Kick Members
Removes members who fail verification, and raiders on your command.
Why we ask, and what breaks
Why we ask
Removes members who exhaust their CAPTCHA attempts, and the raid cohort when a moderator clicks the button on the alert.
What breaks without it
The Kick button on an alert is visible and dead. Your staff do it by hand in another tab while the raid is still arriving.
- Manual bans only
Ban Members
Executes a ban your moderators already decided on.
Why we ask, and what breaks
Why we ask
The Ban button on an impersonation or raid alert, and cohort actions in forensics. Lunaris never bans on its own.
What breaks without it
The same, for bans. This permission only ever executes a decision a human already made, so without it your mods make the decision and then carry it out somewhere else.
- No auto timeouts
Timeout Members
Times out scam senders and spammers, reversibly.
Why we ask, and what breaks
Why we ask
Scam auto-timeout and anti-spam put the sender in a reversible timeout while your staff review, and warnings escalate repeat offenders to one.
What breaks without it
Scam messages are still deleted and alerted, but the sender is not timed out and can post again straight away. Anti-spam can delete but not pause anyone.
- No auto lockdown
Manage Channels
Locks channels during a raid, unlocks them afterward.
Why we ask, and what breaks
Why we ask
Locks channels down during a raid and unlocks them afterwards, and applies the permission fixes setup offers you.
What breaks without it
Lockdown is unavailable, so a raid is handled by hand. Setup can still find topology problems but can only describe them.
- Malicious links stay up
Manage Messages
Deletes messages matching phishing links or your keywords.
Why we ask, and what breaks
Why we ask
Deletes messages that match a scam signature or your keyword list, and runs the purge command.
What breaks without it
The scanner sees the phishing link and posts an alert about it. The link stays up in the channel.
- Anti-nuke goes blind
View Audit Log
Names who deleted a channel, so anti-nuke can act.
Why we ask, and what breaks
Why we ask
Anti-nuke detection. Discord names who deleted a channel only in the audit log, so without reading it a deletion is anonymous.
What breaks without it
Anti-nuke goes blind. It can watch channels disappear and cannot attribute them to an actor, which leaves it nobody to stop.
- Webhooks keep posting
Manage Webhooks
Deletes webhooks an attacker creates during a nuke attempt.
Why we ask, and what breaks
Why we ask
Deletes webhooks a rogue actor created during a nuke attempt, which is how the damage usually continues after the account is contained.
What breaks without it
Containment strips the actor and the webhooks they made keep posting.
- No return path
Create Instant Invite
Creates the one invite a kicked member can use to return.
Why we ask, and what breaks
Why we ask
Creates the one permanent invite the appeal flow hands a removed member. A verified member has DMs closed, so we cannot send them one.
What breaks without it
A member kicked for failing a CAPTCHA has no route back unless you configure an invite yourself.
- Nothing posts
View Channel, Send Messages, Embed Links, Attach Files
Posts the verification panel, CAPTCHA image, and alerts.
Why we ask, and what breaks
Why we ask
Posts the verification panel, the CAPTCHA image, staff alerts and the weekly digest.
What breaks without it
Nothing Lunaris produces reaches your server. The CAPTCHA is an attachment, so it is the first thing to stop working.
- Scanning stops
Read Message History
Lets scanning and the message log read your channels.
Why we ask, and what breaks
Why we ask
Link scanning and the message log read the channels they are pointed at.
What breaks without it
Scanning stops in any channel it cannot read, and the deleted-message log has no before to show you.
- No tickets or help threads
Create Private Threads, Send Messages in Threads, Manage Threads
Runs tickets and verification help in private threads.
Why we ask, and what breaks
Why we ask
Tickets and manual verification each open a private thread with your staff added, and a ticket is locked and archived when it closes.
What breaks without it
A member stuck in verification has nowhere private to ask for help, and tickets cannot open. Closed tickets cannot be locked.
Three things asked for outside the invite.
Permissions are what the bot holds inside your server. These are separate, and two of them are granted by a person rather than by the server.
- identify, guilds
- The dashboard login. It tells us your Discord user id and which servers you can manage, which is how the dashboard knows what to show you. No password and no separate account. Discord does not hand over your email with these scopes, and we do not ask for it.
- applications.commands
- Registers the slash commands. Without it the bot sits in your server and the setup command does not exist.
- guilds.join
- Reunite only, granted by each member, not by you. It re-adds that member to a server you own after a nuke, and nothing else. It expires after 365 days, a member can revoke it any time, and a revoked authorization is deleted, not marked inactive.
What is stored, for how long, and how to delete it.
Lunaris is built to hold as little as it can. This is the whole list, not the categories a privacy policy usually collapses it into.
What we store
Security events 30d free / 90d Pro
Append-only records of what happened: verifications, raid triggers, scan hits, config changes, and the actor behind each one. Your Discord log channel, the weekly digest and forensics all read from this one table. A nightly job deletes rows past the window.
Guild configuration While installed
Channel and role ids, thresholds, feature switches and branding text. Kept after you remove the bot so a re-invite restores your settings instead of starting you over, and deleted on request.
Verification state Minutes
One row per member mid-verification, holding their step and the CAPTCHA answer. Deleted when they finish or when it expires. The answer never travels in a button id, only in that row, server side.
Attempt ledger Until pass or clear
Failed CAPTCHA counts and cooldowns per member, so leaving and rejoining does not reset the count. The count and the cooldown, nothing else about the attempt.
Message log excerpts 30d free / 90d Pro
If you switch message logging on, a deleted or edited message is stored as an event with its author, its channel and its text before and after. Those excerpts are the only message content Lunaris retains, and they age out on the same clock as every other event.
Backups 7 kept
A Pro feature, and nothing exists here unless you use it. A snapshot of channel structure, roles and permissions as JSON, up to 3 per day. No messages and no members.
Threat network reports Fixed window, then dropped
Only if you switch the network on, and it has separate switches for sending and receiving. A report is an account id, one category from a fixed list of five, a timestamp, and the id of the reporting server. There is no free text field in a report, so there is nothing in one that could leak your server.
Reunite authorizations 365d
A token a member granted so they can be restored to a rebuilt server. Encrypted at rest, revocable by the member without asking you, and deleted on revocation or expiry rather than disabled.
What we never store
Your member list
Lunaris sees members as they arrive and acts on them there. It does not copy, export or sell a roster, and there is no feature anywhere in the product that produces one.
Message content, past the excerpts above
No channel is archived. Nothing is read in a channel Lunaris was not pointed at, and nothing read for scanning is written down unless it matched and was acted on.
Anything in the network beyond an id and a category
The threat network carries an account id and one of five categories. Never messages, never your configuration, never your members.
Direct messages
The probe sends one message and deletes it. Lunaris cannot read a member's DMs, is not in them, and receives nothing from them.
Payment details
Stripe holds them. No card number reaches our database, because there is no column for one.
Security event retention, free versus Pro.
How long verifications, raid triggers, scan hits and log excerpts stay before a nightly job deletes them.
How to delete it
- 1
Remove the bot
Verification stops the moment it leaves. Roles already granted stay granted, your channels and permissions are untouched, and your configuration sits dormant in case you come back.
- 2
Ask for an erase
One message in the support server deletes the guild row and every event attached to it. No waiting period, no retention hold, and no offer to keep it for analytics.
- 3
Members can act without you
A member revokes a Reunite authorization themselves and it is deleted, not disabled. An account listed by the threat network has a documented removal and appeal path that does not run through the server that reported it.
Where Lunaris can be fooled.
Every security product has a list like this. Most publish none of it. This one is complete as of today, and a new entry goes here first rather than into a changelog nobody reads.
The DM probe infers a setting it cannot read.
Discord does not expose a member's privacy settings to a bot, so Lunaris tests them instead. On the first verification screen it opens a DM channel with the member, sends one message, and reads what the API says back. The message is deleted immediately, whichever way the answer goes.
The inference has a blind spot, and it is the one worth knowing: a member who has blocked Lunaris specifically produces the same error as a member who locked their DMs, so they pass without locking anything. It is a small population and it is not a door a scammer can walk through, because blocking the bot does not open a channel to anybody else. It is still a member counted as verified who is not protected the way the badge implies.
| API response | What it means | What Lunaris does |
|---|---|---|
| error 50007 | Cannot send messages to this user. | Pass. Advance to the terms screen. |
| error 50278 | No mutual guilds. Returned for DM privacy blocks despite the wording. | Pass. Advance to the terms screen. |
| send succeeds | The member is still reachable by this server. | Fail. Delete the probe, keep them on step one. |
| anything else | Ambiguous. A rate limit, an outage, something new. | Retry once, then stop. Never advance on ambiguity. |
Settings changed after verification are not monitored.
A member can pass the probe and reopen their DMs a minute later. Lunaris will not notice. That is a decision, not a gap we have not reached yet.
Noticing would mean re-probing members on a schedule, which means opening DM channels with hundreds of accounts in a batch. That is the exact fingerprint Discord's anti-spam systems watch for, and it is the exact behavior this product exists to stop. Building it would put every server running Lunaris at risk in order to close a smaller hole, so no mass re-probe exists anywhere in the product and none is going to.
What exists instead is targeted. A staff recheck runs a probe on one member on demand, and adding someone to the watchlist re-probes them automatically and logs the result.
Link scanning matches known patterns, in channels it can see.
The scanner works from a feed of roughly 30,000 known phishing domains per source plus curated scam signatures. It is not a content filter and it does not judge whether a message is a scam. A domain registered an hour ago, a shortener pointing somewhere new, or a scam that never posts a link at all will go straight past it.
It also sees nothing in a channel the bot cannot read, which includes every channel you deliberately hid from it. That is the correct tradeoff, and it is still a tradeoff.
Threat network flags are signals, never proof.
A flag means other Lunaris servers banned that account and categorised why. It does not mean the account did anything in your server, and communities make mistakes, including collectively. So a flag posts an alert carrying the category and the spread, and stops there.
No flag has ever banned anyone, and no single server can flag an account on its own.
Detection alerts. Humans act.
There is no automated ban anywhere in Lunaris. Every ban and kick button sits on an alert and re-authorizes the person who clicks it against Discord's own permissions.
The automatic responses that do exist are containment rather than punishment: a raid lockdown, a quarantine role, a rogue actor stripped mid nuke. All of them are reversible, and that ceiling on what the product can do to your members while you are asleep is deliberate.
Lunaris reduces risk. It cannot eliminate it.
A member can still be talked out of money through a friend request, on another platform, or by somebody already inside your community who nothing here would flag. What this product does is close the largest and most automated of those routes and put evidence in front of your staff for the rest. Anyone promising more than that is describing a product that does not exist.