Skip to content

Trust Centre

Where to find LumenFlow's public trust centre, sub-processors register, live status feed, and the in-product Trust dashboard for compliance packs, residency pinning, and the Article 12 auditor pack.

Public trust centre#

The public trust centre at /trust projects the same enterprise readiness model operators see in the product. Every readiness row — evidence vault, compliance export, org-scoped trust posture, SSO, SAML, and SCIM provisioning — comes from real configuration, not marketing literals. Identity-provider rows reflect the public default (not enabled) until your organisation turns them on. Each row is labelled Live today or Planned.

Related public pages:

  • /subprocessors — versioned register of third-party processors (purpose, region, and an honest DPA column). No customer DPA is signed until one is counter-signed; the change log records every register version.
  • /status — live health of the public API and application database, read from the public health feed. When the feed cannot be reached, every row is marked Unknown. This surface does not invent uptime history, a past-incident feed, or a response-time commitment.

In-product Trust dashboard#

Signed-in operators use Dashboard → Trust (/dashboard/trust) for workspace-scoped trust controls:

ControlWhat it does
Compliance packsSelect or deselect GDPR, HIPAA, finserv, EU AI Act, and sovereign-residency packs per workspace. Changes are audited.
Data residencyEntitled workspaces pin a region (eu_west, us_east, us_west, or apac). Unentitled plans see a refusal explanation and cannot save a pin. Cross-region model calls and residency-relevant storage writes are refused with a residency-violation receipt.
Article 12 auditor packDownload one on-demand evidence pack for EU AI Act Article 12 record-keeping for a chosen workspace.
Audit-trail exportDownload a CSV or JSON projection of the platform audit-event trail — unsigned; see Compliance export.

What these surfaces do not claim#

  • No published support response-time commitment or SLA until one is written into a contract
  • No certification badge — readiness and export surfaces support your own assurance work; they are not a formal conformity assessment
  • No invented uptime history or past-incident feed beyond the live health rows on /status

info For data-handling detail see Compliance & Privacy. For export surfaces see Compliance export. For how to contact us see Getting Support.