This is a sample record for a fictional company. Every clause number (§2.3, §4.1 …) means the same thing on every TrustWarden page, so reviewers can cite it.

Lumen Scheduling

Trust & security record · lumen.example · security@lumen.example
Record · updated 2026-08-09
§1

Company

The service is operated by Lumen Scheduling, Inc. (a fictional company).
stated 2026-08-09
The company is based in Denver, CO, United States.
stated 2026-08-09
Security contact: security@lumen.example.
stated 2026-08-09
§2

Infrastructure

The service runs on Amazon Web Services.
stated 2026-08-09
Customer data is stored in the European Union and the United States.
stated 2026-08-09
All traffic is encrypted in transit (TLS).
stated 2026-08-09
Customer data is encrypted at rest.
stated 2026-08-09
Data is backed up automatically every day, with an off-site copy.
stated 2026-08-09
§3

Data handling

The service processes: account contact data, billing data handled by the payment provider, product usage data.
stated 2026-08-09
After cancellation, customer data is deleted within 30 days.
stated 2026-08-09
Customers can request full deletion of their data.
stated 2026-08-09
§4

Access control

Multi-factor authentication is required on every account with production access.
stated 2026-08-09
Production access is limited to the founders.
stated 2026-08-09
Production access is logged.
stated 2026-08-09
§5

Application security

Customer sign-in supports: email and password, Google/Microsoft sign-in.
stated 2026-08-09
An external penetration test has not been performed yet.
Planned for Q1 next year.
stated 2026-08-09
A responsible-disclosure channel is available for security researchers.
stated 2026-08-09
Dependency and system updates are automated.
stated 2026-08-09
§6

Operations & compliance

Affected customers are notified of security incidents without undue delay (within 72 hours).
stated 2026-08-09
The company holds no formal certifications yet; this page states the current controls directly.
stated 2026-08-09
A Data Processing Agreement is available on request or as a document below.
stated 2026-08-09
The company does not currently carry cyber liability insurance.
stated 2026-08-09
§7

Subprocessors

VendorPurposeRegionTermsSince
Amazon Web Services Application hosting; all service data EU (Ireland) + US (Oregon) DPA 2026-08-09
Stripe Payment processing; billing contact and card data US (global processing) DPA 2026-08-09
Postmark Transactional email; recipient addresses and message content US DPA 2026-08-09
Plausible Web analytics; no cookies, aggregated usage EU DPA 2026-08-09

Subscribe to be notified before this list changes (15-day objection window):

§8

Documents

DocumentTypeSizeAccess
Data Processing Agreement (template) pdf 178 KB Download
Security overview (one page) pdf 94 KB Request access (email + NDA)

Access to gated documents is granted instantly after a confidentiality undertaking; every download is logged.

§9

Change history

DateNoticeRecipients
2026-07-19 Subprocessor list update — 1 added, 0 removed 12