Trust and compliance
Security, supply-chain, data-protection and accessibility documentation for reviewers.
The Trust pack is for procurement officers and security reviewers. It answers the questions that security, data-protection and accessibility checklists ask. Every statement links to the document or code behind it. It is versioned with the repository, and nothing in it is a certification or a claim of compliance.
| Document | What it answers |
|---|---|
| What Lunos claims, and what it doesn’t | The claim table every other document must agree with. CI checks that they do |
| Security overview | Architecture, trust boundaries, and a threat model: what is mitigated and what isn’t |
| Supply chain | How releases are built and how to verify them. How marketplace entries are reviewed |
| CRA readiness | Where Lunos stands under the EU Cyber Resilience Act, the SBOM, vulnerability handling |
| Data protection | GDPR roles, what reaches model providers, and a DPIA-support checklist |
| Accessibility | The accessibility statement and conformance report |
| CSA CAIQ v3.0.1 answers | Pre-filled answers to all 295 CAIQ questions |
Related:
Reporting a vulnerability
Report it privately, never in a public issue:
- through GitHub Security Advisories
- by email to security@lunos.tech
See SECURITY.md.