On July 27, 2026, at 17:56 UTC, the Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate serving the Lucidworks SaaS Platform domains expired. Users attempting to access the SaaS Platform UI at platform.lucidworks.com received certificate errors, and Beacon signal collection via api.lucidworks.com was interrupted. Query serving by underlying search services was not affected, and Lucidworks AI continued to function.
Investigation confirmed that the certificate covering platform.lucidworks.com, api.lucidworks.com, and an internal domain had reached its expiration date without a replacement in place. The certificate was managed through a manual renewal process. Advance expiration warnings did not reach the responsible team, in part due to a delivery failure in the alert-notification pipeline, which is currently under investigation with the relevant vendors.
Lucidworks generated a replacement certificate, completed domain ownership validation, and deployed the new certificate to the affected load balancers. Lucidworks engineers confirmed the new certificate was serving and verified that all affected services had returned to normal operation. Following a period of stable monitoring, the incident was confirmed to be fully resolved at 19:24 UTC.
TLS connections to platform.lucidworks.com, api.lucidworks.com, and an internal Production domain are secured by a shared Subject Alternative Name (SAN) certificate. This certificate was historically issued through a third-party certificate authority and renewed through a manual rotation process. Other Lucidworks domains and services use separate certificates and were not affected.
The certificate reached its expiration date on July 27, 2026, at 17:56 UTC without a replacement having been issued. When the certificate expired, TLS connections to the affected domains failed, rendering the SaaS Platform UI inaccessible and interrupting Beacon signal ingestion.
Advance warning of the expiration existed but did not result in action. A synthetic monitoring test generated a 30-day advance alert on June 27, 2026, which was delivered to an internal alert channel but was not acted upon. The monitoring test continued to run and fire as designed, but beginning on July 1, 2026, alerts stopped being delivered from the monitoring platform to the downstream incident management system, so the scheduled follow-up notifications and pending outage escalations never reached the responsible team. This delivery failure was silent — no monitoring existed on the alert pipeline itself — and is under active investigation with the vendors of our monitoring platform and incident management system.
Review of the response itself found no platform defect. When the expired certificate was identified, replacement issuance, validation, and deployment proceeded without error. As part of the replacement, Lucidworks changed certificate providers rather than renewing through the incumbent certificate authority. Because this was the first certificate issued through the new provider for these domains, Domain Name System (DNS) domain ownership validation was required before the certificate could be issued. This one-time validation requirement increased Lucidworks’ overall time to resolve the issue. Subsequent issuance through this provider will not require repeating this validation step.
Lucidworks has taken or will take the following actions as a result of this incident:
No client action is required. Signals sent to the Beacon endpoint during the incident window (17:56–19:01 UTC on July 27, 2026) were not ingested and are not recoverable. Analytics for this period may reflect a corresponding gap in data or dip in graphs. Clients with questions or observations not described in this report are encouraged to contact Lucidworks Support.