Independent failure domain — served separately from api.preferium.com.
Preferium AI Edge — Trust Center
Customer-facing trust surface, served live at https://trust.preferium.com. This file is the canonical content source — the Astro static Worker (apps/trust/) imports it directly and runs as an independent failure domain with no Supabase, KV or AI Gateway binding.
Control status
Every row below is generated from the control registry in packages/shared/src/trust-controls.ts and checked by node scripts/check-trust-controls.mjs. Nothing here is a certification, and nothing here is a plan presented as a fact.
A control is Active only when three separate things are true: the code is implemented, its behaviour is tested, and its configuration has been read back in the environment it protects. Source code that exists is not a configuration that was verified. Anything short of all three is Limited, even when the implementation is complete — which is why every runtime control on this page reads Limited today. Planned means the work has not been done at all.
Control evidence observed: 2026-09-11 · Next review due: 2026-12-10 · Control owner: Robert André Johansen (post@preferium.no)
| Control | Status | What is actually true today |
|---|---|---|
GDPR-FRAMEWORK-001 |
Limited | the contractual framework is published: DPA, subprocessor register and Article 30 records. The operational controls behind them have not been audited by anyone outside Preferium. |
DATA-RESIDENCY-EU-001 |
Limited | the primary data plane is configured for a Supabase EU region, and edge delivery is global by design. We publish no provider readback proving where every byte sat on a given day. |
ENCRYPTION-001 |
Limited | TLS with HSTS is set on every response by shared header code under test, and integration tokens are encrypted before storage. Encryption at rest is provider-managed and taken on the provider contract, not measured by us. |
MFA-PRIVILEGED-001 |
Limited | the privileged-role gate is implemented and unit-tested, and an unset or invalid mode resolves to the fail-closed default in production. We have not read back a production configuration or a privileged-user enrolment, so we do not claim multi-factor authentication is in force. |
SSO-SAML-001 |
Limited | SAML 2.0 SP-initiated login with IdP metadata and InResponseTo binding is implemented, plan-gated and unit-tested. No customer identity provider has been configured end to end, so Enterprise single sign-on is not yet in service. |
AUDIT-CHAIN-001 |
Limited | sensitive actions append to a hash-chained audit log whose chain integrity is enforced by a database trigger, and repository guards keep the coverage honest. No external party has verified a production chain. |
BACKUP-CAPTURE-001 |
Limited | Read-only production observation on 2026-09-19 found 115 completed legacy backup-run records (last 2026-09-16), but no active replacement capture snapshot/epoch/chain, capture outcome or export snapshots. Legacy records do not verify retained object completeness or restorability. No signed, witnessed production capture is evidenced. Managed backup/PITR configuration is unknown because the observer lacks a least-privileged backups_read credential. Local fixture artifacts do not prove independent provider copies. |
BACKUP-RESTORE-001 |
Limited | the restore path was rehearsed end to end on 2026-09-11 against disposable local databases and in-memory buckets: 49 probes passed and crash-and-resume converged exactly once. It has never run against a provider, and the local duration is not a recovery time objective. |
DR-RESIDUAL-001 |
Limited | total loss of the managed database, authentication and point-in-time-recovery domain is UNRECOVERABLE for complete authentication even if Cloudflare and R2 survive. What our own capture can replay is object metadata, which is a partial recovery of public and object state, not a managed whole-database recovery. This residual is tracked as DR-RESIDUAL-001 and stays limited until an independently administered encrypted authentication export and import leg is built and rehearsed. |
RECOVERY-OBJECTIVES-001 |
Limited | Declared targets remain 300 s for managed database/authentication PITR, 3600 s for consistent database/customer objects and open money/provider/citation/route state, and 86400 s for forensic history. A recovery point objective is measured as observation time minus the time actually captured through, never as the age of a successful manifest. Observed production recovery points and recovery times remain unknown rather than met: no verified captured-through frontier or provider restore proves them. A completed legacy run or local fixture duration does not establish an achieved objective. |
STATUS-PAGE-001 |
Limited | status.preferium.com is a self-hosted worker in its own failure domain that renders the live health aggregate and says so when it cannot reach it. It stores no history, publishes no feed and sends no notifications. We use no third-party status-page product and offer no subscription of any kind. |
SBOM-PROVENANCE-001 |
Limited | the CycloneDX SBOM and signed build-provenance workflow is committed, but it triggers only on a release tag and no tag has been cut. Nothing has been generated, signed or published, so there is no artifact to download and no attestation to verify. |
CCPA-001 |
Limited | service-provider and contractor duties are covered in the DPA and Privacy Notice. Applicability and request handling are assessed per customer and per data flow rather than certified. |
PENTEST-EXTERNAL-001 |
Planned | no external penetration test has been performed. The first engagement is in vendor selection and no summary exists. We will publish one when a test has actually happened. |
SOC2-TYPE2-001 |
Planned | not started. Evidence automation is not contracted, no observation window has begun and no date is set. A target date appears here when an engagement is signed. |
Not in scope
These are not controls and are not on a roadmap. We say so rather than leaving an empty row that reads like work in progress.
- ISO 27001 — deferred, to be re-evaluated on customer demand. No ISMS programme exists. Most Nordic mid-market buyers accept SOC 2 alone, and SOC 2 has not started either.
- HIPAA — out of scope. Preferium AI Edge is not built for healthcare workloads and we do not accept protected health information.
- FedRAMP — out of scope. We are not pursuing US federal workloads.
Available artifacts (downloads)
| Artifact | Format | Notes |
|---|---|---|
| Data Processing Agreement (DPA) | Published on preferium.com | Article 28 contract intended for incorporation by signed Order, separate signature or evidenced authorised Dashboard acceptance; a counter-signed copy is available on request. |
| Privacy Notice | Published on preferium.com | Public-facing privacy notice for Preferium.com properties and the Service. |
| Service Terms | Published on preferium.com | Core B2B terms for every plan, supplemented by the Order, Agency Addendum, DPA, AUP and expressly incorporated schedules under the stated order of precedence. |
| Vulnerability Disclosure Policy (VDP) | Markdown → HTML | RFC 9116 safe-harbor, scope and response targets, advertised via /.well-known/security.txt. Published as a draft pending legal review — the safe-harbor commitment in §3 is offered as written. |
| Subprocessor register | Published on preferium.com | Maintained for GDPR Art. 28. 30-day change notice and objection process under the DPA §6. |
| GDPR Article 30 records of processing | Markdown → PDF on deploy | Records identified controller and processor activities; relevant extracts are available on request. |
| Software Bill of Materials (SBOM) | CycloneDX JSON | Nothing to download. The pipeline is committed but has never run — see SBOM-PROVENANCE-001 above and /sbom/. Request the current dependency inventory by email instead. |
| Artifact attestations | SLSA provenance | Nothing to download. Same pipeline, same reason. Details at /sbom/. |
| Penetration test summary | Does not exist — no test has been performed. See PENTEST-EXTERNAL-001 above. |
|
| Status page | self-hosted worker | The current health of the platform services, read live. It stores no history and sends nothing — see STATUS-PAGE-001 above. |
Security disclosures
- Report vulnerabilities per the VDP at
security@preferium.com(or via/.well-known/security.txtinstructions). - We follow coordinated disclosure with a 90-day default disclosure window (negotiable), as
published in the VDP —
docs/legal/VDP-policy.mdowns the figure. - Safe harbor: good-faith research per VDP §3 is not subject to legal action.
- Bug bounty: we do not currently offer monetary bounties, and no formal bug-bounty program exists yet.
Sub-processors
The active register, with each provider’s purpose, location and transfer basis, is published at preferium.com/subprocessors — the only canonical copy; this trust centre does not repeat it. Changes are announced there with a 30-day notice per the DPA.
Privacy Contact and DPO assessment
Preferium AS has not appointed a Data Protection Officer under GDPR Article 37. The current assessment is recorded in docs/legal/dpo-designation.md and must be revisited if the scale, nature or legal classification of processing changes.
Robert André Johansen is the operational Privacy Contact. As founder and chief executive he is not represented as an independent DPO. Privacy requests and supervisory-authority communications use the public legal/privacy contact below.
Contact: post@preferium.no.
Incident response
- Breach detection: Sentry error monitoring plus AI Gateway error-rate alerting. Both are operator-facing; neither is a customer notification channel.
- Notification SLA: GDPR Art. 33 — Supervisory authority (Datatilsynet) within 72 hours. Affected customers concurrently.
- Runbook:
RUNBOOK.md§2 (incident playbooks per failure mode). - Recovery rehearsal: the restore path was rehearsed against disposable local databases and in-memory buckets on 2026-09-11; the report is in
docs/dr-drills/. Production observation on 2026-09-19 found zero restore preparations and restore runs. No provider rehearsal or verified production capture is evidenced. The local rehearsal proves the tested code path, not recovery of this service or a kept operational drill cadence. - Latest post-mortem: None — no incidents have occurred that required one.
Changelog
There is no changelog page and no subscription mechanism. Sub-processor changes are announced on preferium.com/subprocessors with 30 days’ notice per the DPA, and the change log in gdpr-article-30-records.md §H records what changed and when.
Contact
- Security disclosures:
security@preferium.com(per VDP) - Privacy Contact, DPA & legal:
post@preferium.no - General trust questions:
trust@preferium.com(alias to current responsible party)