Trust

Trust and security documentation

For procurement and security reviewers: what Lunos does, what it doesn't, and where each statement is backed. Lunos holds no certification and claims none.

Documents

The Trust pack

DocumentCoversStatus
Security overviewArchitecture, trust boundaries, and a threat model: prompt injection, tool execution, supply chain, secrets, the audit logPublished. Each threat says what is mitigated and what is not
Supply chainHow releases are built, how to verify them, the SBOM, and marketplace reviewPublished. npm provenance, and Sigstore-signed checksums from v1.18.40; no OS code signing
EU Cyber Resilience ActScope assessment and readiness: SBOM, vulnerability handling, support periodsPublished. Likely outside CRA scope; support periods not yet defined
Data protection (GDPR)Controller and processor roles, data sent to model providers, a DPIA checklistPublished. Reviewed by counsel
AccessibilityEN 301 549 / WCAG 2.1 AA statement and conformance reportNot yet published. Audit in progress
CSA CAIQ v3.0.1 answersPre-filled answers to all 295 questions, with a spreadsheet copyPublished. Organisational questions are marked for ITService EOOD to answer

Statements apply to the latest release, v1.18.40, unless marked "from the next release". The pack is versioned with the source; the authoritative copy is docs/trust in the repository.

Where your data goes

Lunos is self-hosted: ITService EOOD runs no service in the data path and there is no telemetry. The full account is in the self-hosted deployment guide.