3-week structured review
Buyer evaluation kit
A repeatable playbook for security, procurement, and legal teams evaluating Lumiaxiom. Every item is time-boxed and mapped to an artifact we already produce — no scavenger hunts, no gated PDFs.
Week 0 — Kickoff
Buyer + Lumiaxiom
- Executed mutual NDA (2-page template available)
- Named security, procurement, and technical points of contact
- Confirm frameworks in scope: SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act, DORA
- Confirm target close date and pilot success criteria
Week 1 — Documentation review
Buyer security team
- Pre-filled SIG Lite (2024) and CAIQ v4 delivered
- Public policies: /security/policies
- Data retention: /security/data-retention
- Sub-processor register + framework status: /trust
- SBOM (SPDX) and most-recent pen-test executive summary
Week 1 — Legal review
Buyer legal / DPO
- DPA with EU Standard Contractual Clauses (redlines welcome)
- MSA / order form review
- Data flow diagram and cross-border transfer justification
- Insurance certificates (cyber, E&O, general liability)
Week 2 — Technical evaluation
Buyer engineering / IT
- Sandbox tenant with sample data + a demo GitHub org
- Run the code-scan pipeline against a pilot repository
- Verify hash-chained evidence ledger with the CLI verifier
- Test SSO (OIDC/SAML) + SCIM against your IdP
- Auditor-portal walkthrough (scoped, time-bound grant)
Week 3 — Decision
Buyer + Lumiaxiom
- Written responses to any remaining questionnaire items
- Reference calls with two existing customers in your industry
- Executive summary: control coverage, gaps, remediation plan
- Signed order form + kickoff for production onboarding
Control-by-control checklist
Copy this straight into your assessment tracker. Every question maps to an artifact linked from the evidence page.
| Area | Ask |
|---|---|
| Access control | How is customer data segregated? What does an admin escalation look like? |
| Encryption | What algorithms are in use in transit and at rest? Who holds the keys? |
| SDLC | How do code changes reach production? Any manual override paths? |
| Source code handling | Do you store or train on customer source code? Prove it. |
| Incident response | What are your SLOs? Show me a redacted post-mortem. |
| Sub-processors | Full list, region, and notice period for changes. |
| Data residency | Where can data be stored? What controls enforce it? |
| Retention & deletion | How is a tenant purged? What proves it happened? |
| Audit & evidence | How is evidence tamper-evident? Can we verify offline? |
| AI governance | How do you meet EU AI Act and NIST AI RMF obligations for your own AI features? |
Start your evaluation
Email security@lumiaxiom.com with your NDA template and target close date. You'll receive the SIG Lite, CAIQ, SBOM, and pen-test summary inside one business day.
Related