Skip to content

Transparency

Lunaris asks for permissions that could hurt you.Here is exactly what it does with them.

Handing Manage Roles, Kick Members, Ban Members, Manage Channels and View Audit Log to a developer you have never met is a real risk, and pretending otherwise would be the first thing worth distrusting. Below: every permission and what breaks without it, every field stored and for how long, and every place the product can be fooled. Read it before you install, not after something goes wrong.

Every permission, and what breaks without it.

Tap a card for why Lunaris asks and exactly what stops working if you refuse it. A permission with no consequence attached to its absence is a permission that was taken because it was easy to ask for.

Lunaris asks for Administrator. Here is what it actually uses.

A security bot that cannot reach a channel, a role or a webhook is a security bot with a blind spot, and a missing permission is the most common reason a protection silently does nothing during the attack it was installed for. Administrator closes that gap in one step. Every permission Lunaris actually exercises is listed below with what it does and what would break without it, so you can see exactly where that authority goes.

  • Verification blocked

    Manage Roles

    Grants the verified role, strips attacker roles during a nuke.

    Why we ask, and what breaks

    Why we ask

    Grants the verified role when a member passes, applies the quarantine role, and strips a rogue actor's roles while a nuke is in progress.

    What breaks without it

    Verification runs and then cannot let anyone in. Anti-nuke still detects the attack and still alerts, but it cannot take the attacker's roles away while it is happening.

  • Manual removal only

    Kick Members

    Removes members who fail verification, and raiders on your command.

    Why we ask, and what breaks

    Why we ask

    Removes members who exhaust their CAPTCHA attempts, and the raid cohort when a moderator clicks the button on the alert.

    What breaks without it

    The Kick button on an alert is visible and dead. Your staff do it by hand in another tab while the raid is still arriving.

  • Manual bans only

    Ban Members

    Executes a ban your moderators already decided on.

    Why we ask, and what breaks

    Why we ask

    The Ban button on an impersonation or raid alert, and cohort actions in forensics. Lunaris never bans on its own.

    What breaks without it

    The same, for bans. This permission only ever executes a decision a human already made, so without it your mods make the decision and then carry it out somewhere else.

  • No auto timeouts

    Timeout Members

    Times out scam senders and spammers, reversibly.

    Why we ask, and what breaks

    Why we ask

    Scam auto-timeout and anti-spam put the sender in a reversible timeout while your staff review, and warnings escalate repeat offenders to one.

    What breaks without it

    Scam messages are still deleted and alerted, but the sender is not timed out and can post again straight away. Anti-spam can delete but not pause anyone.

  • No auto lockdown

    Manage Channels

    Locks channels during a raid, unlocks them afterward.

    Why we ask, and what breaks

    Why we ask

    Locks channels down during a raid and unlocks them afterwards, and applies the permission fixes setup offers you.

    What breaks without it

    Lockdown is unavailable, so a raid is handled by hand. Setup can still find topology problems but can only describe them.

  • Malicious links stay up

    Manage Messages

    Deletes messages matching phishing links or your keywords.

    Why we ask, and what breaks

    Why we ask

    Deletes messages that match a scam signature or your keyword list, and runs the purge command.

    What breaks without it

    The scanner sees the phishing link and posts an alert about it. The link stays up in the channel.

  • Anti-nuke goes blind

    View Audit Log

    Names who deleted a channel, so anti-nuke can act.

    Why we ask, and what breaks

    Why we ask

    Anti-nuke detection. Discord names who deleted a channel only in the audit log, so without reading it a deletion is anonymous.

    What breaks without it

    Anti-nuke goes blind. It can watch channels disappear and cannot attribute them to an actor, which leaves it nobody to stop.

  • Webhooks keep posting

    Manage Webhooks

    Deletes webhooks an attacker creates during a nuke attempt.

    Why we ask, and what breaks

    Why we ask

    Deletes webhooks a rogue actor created during a nuke attempt, which is how the damage usually continues after the account is contained.

    What breaks without it

    Containment strips the actor and the webhooks they made keep posting.

  • No return path

    Create Instant Invite

    Creates the one invite a kicked member can use to return.

    Why we ask, and what breaks

    Why we ask

    Creates the one permanent invite the appeal flow hands a removed member. A verified member has DMs closed, so we cannot send them one.

    What breaks without it

    A member kicked for failing a CAPTCHA has no route back unless you configure an invite yourself.

  • Nothing posts

    View Channel, Send Messages, Embed Links, Attach Files

    Posts the verification panel, CAPTCHA image, and alerts.

    Why we ask, and what breaks

    Why we ask

    Posts the verification panel, the CAPTCHA image, staff alerts and the weekly digest.

    What breaks without it

    Nothing Lunaris produces reaches your server. The CAPTCHA is an attachment, so it is the first thing to stop working.

  • Scanning stops

    Read Message History

    Lets scanning and the message log read your channels.

    Why we ask, and what breaks

    Why we ask

    Link scanning and the message log read the channels they are pointed at.

    What breaks without it

    Scanning stops in any channel it cannot read, and the deleted-message log has no before to show you.

  • No tickets or help threads

    Create Private Threads, Send Messages in Threads, Manage Threads

    Runs tickets and verification help in private threads.

    Why we ask, and what breaks

    Why we ask

    Tickets and manual verification each open a private thread with your staff added, and a ticket is locked and archived when it closes.

    What breaks without it

    A member stuck in verification has nowhere private to ask for help, and tickets cannot open. Closed tickets cannot be locked.

Three things asked for outside the invite.

Permissions are what the bot holds inside your server. These are separate, and two of them are granted by a person rather than by the server.

identify, guilds
The dashboard login. It tells us your Discord user id and which servers you can manage, which is how the dashboard knows what to show you. No password and no separate account. Discord does not hand over your email with these scopes, and we do not ask for it.
applications.commands
Registers the slash commands. Without it the bot sits in your server and the setup command does not exist.
guilds.join
Reunite only, granted by each member, not by you. It re-adds that member to a server you own after a nuke, and nothing else. It expires after 365 days, a member can revoke it any time, and a revoked authorization is deleted, not marked inactive.

What is stored, for how long, and how to delete it.

Lunaris is built to hold as little as it can. This is the whole list, not the categories a privacy policy usually collapses it into.

What we store

  • Security events 30d free / 90d Pro

    Append-only records of what happened: verifications, raid triggers, scan hits, config changes, and the actor behind each one. Your Discord log channel, the weekly digest and forensics all read from this one table. A nightly job deletes rows past the window.

  • Guild configuration While installed

    Channel and role ids, thresholds, feature switches and branding text. Kept after you remove the bot so a re-invite restores your settings instead of starting you over, and deleted on request.

  • Verification state Minutes

    One row per member mid-verification, holding their step and the CAPTCHA answer. Deleted when they finish or when it expires. The answer never travels in a button id, only in that row, server side.

  • Attempt ledger Until pass or clear

    Failed CAPTCHA counts and cooldowns per member, so leaving and rejoining does not reset the count. The count and the cooldown, nothing else about the attempt.

  • Message log excerpts 30d free / 90d Pro

    If you switch message logging on, a deleted or edited message is stored as an event with its author, its channel and its text before and after. Those excerpts are the only message content Lunaris retains, and they age out on the same clock as every other event.

  • Backups 7 kept

    A Pro feature, and nothing exists here unless you use it. A snapshot of channel structure, roles and permissions as JSON, up to 3 per day. No messages and no members.

  • Threat network reports Fixed window, then dropped

    Only if you switch the network on, and it has separate switches for sending and receiving. A report is an account id, one category from a fixed list of five, a timestamp, and the id of the reporting server. There is no free text field in a report, so there is nothing in one that could leak your server.

  • Reunite authorizations 365d

    A token a member granted so they can be restored to a rebuilt server. Encrypted at rest, revocable by the member without asking you, and deleted on revocation or expiry rather than disabled.

What we never store

  • Your member list

    Lunaris sees members as they arrive and acts on them there. It does not copy, export or sell a roster, and there is no feature anywhere in the product that produces one.

  • Message content, past the excerpts above

    No channel is archived. Nothing is read in a channel Lunaris was not pointed at, and nothing read for scanning is written down unless it matched and was acted on.

  • Anything in the network beyond an id and a category

    The threat network carries an account id and one of five categories. Never messages, never your configuration, never your members.

  • Direct messages

    The probe sends one message and deletes it. Lunaris cannot read a member's DMs, is not in them, and receives nothing from them.

  • Payment details

    Stripe holds them. No card number reaches our database, because there is no column for one.

Security event retention, free versus Pro.

How long verifications, raid triggers, scan hits and log excerpts stay before a nightly job deletes them.

Free
30d
Pro
90d

How to delete it

  1. 1

    Remove the bot

    Verification stops the moment it leaves. Roles already granted stay granted, your channels and permissions are untouched, and your configuration sits dormant in case you come back.

  2. 2

    Ask for an erase

    One message in the support server deletes the guild row and every event attached to it. No waiting period, no retention hold, and no offer to keep it for analytics.

  3. 3

    Members can act without you

    A member revokes a Reunite authorization themselves and it is deleted, not disabled. An account listed by the threat network has a documented removal and appeal path that does not run through the server that reported it.

Where Lunaris can be fooled.

Every security product has a list like this. Most publish none of it. This one is complete as of today, and a new entry goes here first rather than into a changelog nobody reads.

The DM probe infers a setting it cannot read.

Discord does not expose a member's privacy settings to a bot, so Lunaris tests them instead. On the first verification screen it opens a DM channel with the member, sends one message, and reads what the API says back. The message is deleted immediately, whichever way the answer goes.

The inference has a blind spot, and it is the one worth knowing: a member who has blocked Lunaris specifically produces the same error as a member who locked their DMs, so they pass without locking anything. It is a small population and it is not a door a scammer can walk through, because blocking the bot does not open a channel to anybody else. It is still a member counted as verified who is not protected the way the badge implies.

What the probe reads, and what it does with it
API responseWhat it meansWhat Lunaris does
error 50007Cannot send messages to this user.Pass. Advance to the terms screen.
error 50278No mutual guilds. Returned for DM privacy blocks despite the wording.Pass. Advance to the terms screen.
send succeedsThe member is still reachable by this server.Fail. Delete the probe, keep them on step one.
anything elseAmbiguous. A rate limit, an outage, something new.Retry once, then stop. Never advance on ambiguity.

Settings changed after verification are not monitored.

A member can pass the probe and reopen their DMs a minute later. Lunaris will not notice. That is a decision, not a gap we have not reached yet.

Noticing would mean re-probing members on a schedule, which means opening DM channels with hundreds of accounts in a batch. That is the exact fingerprint Discord's anti-spam systems watch for, and it is the exact behavior this product exists to stop. Building it would put every server running Lunaris at risk in order to close a smaller hole, so no mass re-probe exists anywhere in the product and none is going to.

What exists instead is targeted. A staff recheck runs a probe on one member on demand, and adding someone to the watchlist re-probes them automatically and logs the result.

Link scanning matches known patterns, in channels it can see.

The scanner works from a feed of roughly 30,000 known phishing domains per source plus curated scam signatures. It is not a content filter and it does not judge whether a message is a scam. A domain registered an hour ago, a shortener pointing somewhere new, or a scam that never posts a link at all will go straight past it.

It also sees nothing in a channel the bot cannot read, which includes every channel you deliberately hid from it. That is the correct tradeoff, and it is still a tradeoff.

Threat network flags are signals, never proof.

A flag means other Lunaris servers banned that account and categorised why. It does not mean the account did anything in your server, and communities make mistakes, including collectively. So a flag posts an alert carrying the category and the spread, and stops there.

No flag has ever banned anyone, and no single server can flag an account on its own.

Detection alerts. Humans act.

There is no automated ban anywhere in Lunaris. Every ban and kick button sits on an alert and re-authorizes the person who clicks it against Discord's own permissions.

The automatic responses that do exist are containment rather than punishment: a raid lockdown, a quarantine role, a rogue actor stripped mid nuke. All of them are reversible, and that ceiling on what the product can do to your members while you are asleep is deliberate.

Lunaris reduces risk. It cannot eliminate it.

A member can still be talked out of money through a friend request, on another platform, or by somebody already inside your community who nothing here would flag. What this product does is close the largest and most automated of those routes and put evidence in front of your staff for the rest. Anyone promising more than that is describing a product that does not exist.

Install it with your eyes open.