Regulated trust posture

What is live in the regulated-industry governance tier, what is in progress, and which procurement and SOC 2 claims are still explicitly planned.

Regulated-industry posture, stated carefully#

The regulated-industry tier is the agent-governance layer for teams that need cryptographic evidence, policy-gated execution, operator sign-off, residency proof, and reproducible audit bundles.

It is not a certification claim. Do not say LumenFlow is SOC2 Type II certified, HIPAA certified, or procurement-ready for SAML/SCIM until the corresponding live controls and external evidence exist.

Live or shipped substrate#

AreaCurrent posture
Control mapExplicit claims guardrails are published: don't call anything certified or attested without live evidence backing the claim
Cryptographic evidenceEvidence receipts are anchored with a Merkle-style chain so historical tampering can be detected
Compliance gatesGDPR, HIPAA, and finserv packs can fail closed through the gate-resolver path with auditable decline events
Operator sign-offMid-execution pause/resume/reject flows compose with dispatch leases and checkpoint events
Enterprise authSAML sign-in, SCIM provisioning, and MFA (step-up authentication) policy are live and API-configurable — see Enterprise Trust

In progress or planned#

AreaBoundary
Audit bundlesScheduled bundle generation is in progress; generated bundles are evidence packages, not attestations
Data residencyKey-region, storage-region, and evidence-bound routing controls are in progress; labels alone are not enforcement
Enterprise auth settings UIA dedicated dashboard page for configuring SAML/SCIM (in place of today's API-only configuration) is planned; there's no certified integration with a named identity provider yet
SOC 2 drillThe SOC 2 Type II external audit drill is planned after P1-P7 evidence exists; public claims require security/legal approval

Public wording#

Use "regulated-industry agent governance tier" or "regulated trust posture." Avoid "certified" or "attested" unless a specific live control and evidence package supports that sentence. SAML sign-in, SCIM provisioning, and MFA policy are live controls — say so plainly — but a full enterprise procurement checklist (named-IdP certification, formal audit attestation) is still in progress.