Skip to content

Trust and compliance

Security, supply-chain, data-protection and accessibility documentation for reviewers.

The Trust pack is for procurement officers and security reviewers. It answers the questions that security, data-protection and accessibility checklists ask. Every statement links to the document or code behind it. It is versioned with the repository, and nothing in it is a certification or a claim of compliance.

DocumentWhat it answers
What Lunos claims, and what it doesn’tThe claim table every other document must agree with. CI checks that they do
Security overviewArchitecture, trust boundaries, and a threat model: what is mitigated and what isn’t
Supply chainHow releases are built and how to verify them. How marketplace entries are reviewed
CRA readinessWhere Lunos stands under the EU Cyber Resilience Act, the SBOM, vulnerability handling
Data protectionGDPR roles, what reaches model providers, and a DPIA-support checklist
AccessibilityThe accessibility statement and conformance report
CSA CAIQ v3.0.1 answersPre-filled answers to all 295 CAIQ questions

Related:

Reporting a vulnerability

Report it privately, never in a public issue:

See SECURITY.md.