About the Lumvale capture
Last reviewed: September 2026
If a request in your logs carries this user agent, it came from us:
LumvaleRiskCohortCapture/1.0 (+https://www.lumvale.com/bot)
Who we are and why we visit
We are Lumvale Group Pty Ltd. We are calibrating a vendor-risk scoring model against publicly disclosed breach outcomes, which means we need to know what the model would have said about a set of ordinary domains chosen in advance. Your domain may be in that set.
This is research. It is not marketing, advertising or sales prospecting, we are not building a mailing list, and nothing we collect is sold or used to contact you.
What we collect
Passive signals only:
- Certificate transparency records, read from public CT logs — not from your site.
- DNS records: CAA, MX, SPF, DMARC and MTA-STS, read from a recursive resolver.
- DNS blocklist lookups for the address your domain resolves to.
- One ordinary HTTPS GET of your home page, following redirects. We read the response headers and discard the body without downloading it.
Only the last of those reaches your server at all. We do not scan ports, probe for vulnerabilities, attempt logins, submit forms, or collect personal data. The code that does this cannot open a raw socket: it is built against DNS and fetch only, and the build fails if anything that could open one is added to it.
How often you see us
A capture window is 28 days, and within a window each domain is fetched at most once. So in practice that is a single HTTPS request per domain per 28-day window at most — not a daily visit. One pass over the whole set takes weeks rather than hours, and once your domain has been fetched in a window we do not come back until the next one. Requests are paced deliberately slowly — a minimum gap between any two requests we make, a five-minute cooldown before we would contact the same host again, and at most two requests in flight across the whole run.
If you refuse us — an HTTP 429 or 403, or a dropped connection — we back off exponentially and stop contacting your host entirely after three refusals.
How to be excluded
Tell us the domain and we will remove it from the set. Email abuse@lumvale.com (or use our contact form), mention this page, and include the domain you want excluded. We honour exclusion requests: the domain is removed from the list we capture, and we do not ask again.
You do not have to explain why, and blocking or rate-limiting us at your edge is also fine — we treat that as a refusal and stop.
Questions or complaints
Same route: email abuse@lumvale.com or use our contact form. If something we did looks wrong in your logs, please tell us and we will look at it.