This is a sample record for a fictional company. Every clause number (§2.3, §4.1 …) means the same thing on every TrustWarden page, so reviewers can cite it.
Lumen Scheduling
§1
Company
§2
Infrastructure
§3
Data handling
The service processes: account contact data, billing data handled by the payment provider, product usage data.
stated 2026-08-09
§4
Access control
Multi-factor authentication is required on every account with production access.
stated 2026-08-09
§5
Application security
An external penetration test has not been performed yet.
Planned for Q1 next year.
stated 2026-08-09
§6
Operations & compliance
Affected customers are notified of security incidents without undue delay (within 72 hours).
stated 2026-08-09
The company holds no formal certifications yet; this page states the current controls directly.
stated 2026-08-09
§7
Subprocessors
| Vendor | Purpose | Region | Terms | Since |
|---|---|---|---|---|
| Amazon Web Services | Application hosting; all service data | EU (Ireland) + US (Oregon) | DPA | 2026-08-09 |
| Stripe | Payment processing; billing contact and card data | US (global processing) | DPA | 2026-08-09 |
| Postmark | Transactional email; recipient addresses and message content | US | DPA | 2026-08-09 |
| Plausible | Web analytics; no cookies, aggregated usage | EU | DPA | 2026-08-09 |
Subscribe to be notified before this list changes (15-day objection window):
§8
Documents
| Document | Type | Size | Access |
|---|---|---|---|
| Data Processing Agreement (template) | 178 KB | Download | |
| Security overview (one page) | 94 KB | Request access (email + NDA) |
Access to gated documents is granted instantly after a confidentiality undertaking; every download is logged.
§9
Change history
| Date | Notice | Recipients |
|---|---|---|
| 2026-07-19 | Subprocessor list update — 1 added, 0 removed | 12 |