Security/Evaluation kit
3-week structured review

Buyer evaluation kit

A repeatable playbook for security, procurement, and legal teams evaluating Lumiaxiom. Every item is time-boxed and mapped to an artifact we already produce — no scavenger hunts, no gated PDFs.

Week 0 — Kickoff

Buyer + Lumiaxiom
  • Executed mutual NDA (2-page template available)
  • Named security, procurement, and technical points of contact
  • Confirm frameworks in scope: SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act, DORA
  • Confirm target close date and pilot success criteria

Week 1 — Documentation review

Buyer security team
  • Pre-filled SIG Lite (2024) and CAIQ v4 delivered
  • Public policies: /security/policies
  • Data retention: /security/data-retention
  • Sub-processor register + framework status: /trust
  • SBOM (SPDX) and most-recent pen-test executive summary

Week 1 — Legal review

Buyer legal / DPO
  • DPA with EU Standard Contractual Clauses (redlines welcome)
  • MSA / order form review
  • Data flow diagram and cross-border transfer justification
  • Insurance certificates (cyber, E&O, general liability)

Week 2 — Technical evaluation

Buyer engineering / IT
  • Sandbox tenant with sample data + a demo GitHub org
  • Run the code-scan pipeline against a pilot repository
  • Verify hash-chained evidence ledger with the CLI verifier
  • Test SSO (OIDC/SAML) + SCIM against your IdP
  • Auditor-portal walkthrough (scoped, time-bound grant)

Week 3 — Decision

Buyer + Lumiaxiom
  • Written responses to any remaining questionnaire items
  • Reference calls with two existing customers in your industry
  • Executive summary: control coverage, gaps, remediation plan
  • Signed order form + kickoff for production onboarding

Control-by-control checklist

Copy this straight into your assessment tracker. Every question maps to an artifact linked from the evidence page.

AreaAsk
Access controlHow is customer data segregated? What does an admin escalation look like?
EncryptionWhat algorithms are in use in transit and at rest? Who holds the keys?
SDLCHow do code changes reach production? Any manual override paths?
Source code handlingDo you store or train on customer source code? Prove it.
Incident responseWhat are your SLOs? Show me a redacted post-mortem.
Sub-processorsFull list, region, and notice period for changes.
Data residencyWhere can data be stored? What controls enforce it?
Retention & deletionHow is a tenant purged? What proves it happened?
Audit & evidenceHow is evidence tamper-evident? Can we verify offline?
AI governanceHow do you meet EU AI Act and NIST AI RMF obligations for your own AI features?
Start your evaluation

Email security@lumiaxiom.com with your NDA template and target close date. You'll receive the SIG Lite, CAIQ, SBOM, and pen-test summary inside one business day.

Related