Evidence artifacts
Two tiers: artifacts you can read right now, and artifacts we send under NDA. If your assessment team needs something not listed, email security@lumiaxiom.com — we usually respond within one business day.
Public artifacts
Current list of vendors that process customer data on our behalf, with purpose and region.
Live status for SOC 2 Type II, ISO 27001, EU AI Act, GDPR — including audit windows.
Public summaries of access, encryption, SDLC, incident response, and personnel policies.
How long each data class is retained, tenant-controlled purge, and export windows.
Every material product and security change, dated. Reviewers rely on this for evidence freshness.
Under NDA
These artifacts are sent after an executed mutual NDA. Most reviews close in under 48 hours; enterprise legal templates are honored.
- SIG Lite response
Pre-filled Shared Assessments SIG Lite (2024 revision) covering ~330 controls.
- CAIQ v4 response
Cloud Security Alliance CAIQ v4 answers with control-by-control evidence links.
- Penetration test summary
Executive summary of our most recent third-party pen test, with remediation status.
- SOC 2 Type II report
Available on request under NDA once our current Type II observation window closes.
- Software Bill of Materials (SBOM)
SPDX-format SBOM for the Lumiaxiom platform, refreshed on every production release.
- Full security policies (unabridged)
Complete text of the policies summarized on the public policies page.
- Signed evidence bundle
Hash-chained export of your tenant's evidence ledger, verifiable offline with our CLI.
- Data Processing Addendum (DPA)
Standard DPA (EU SCCs included) — request a signed copy or reference our public /dpa page.
Send your questionnaire, NDA template, or specific control asks to security@lumiaxiom.com. Include the frameworks in scope (SOC 2, ISO 27001, HIPAA, GDPR, EU AI Act, DORA, etc.) and your target close date.