Last updated 2026-05-21 (R174 content) — independent failure domain from api.preferium.com.

Preferium AI Edge — Trust Center

Customer-facing surface that will be served at trust.preferium.com post-deploy. This file is the canonical content source — the Astro static Worker (apps/trust/ — planned R175+) pulls from this and the linked legal/trust documents.

Last updated: 2026-05-21 (R174)


At a glance

ControlStatus
GDPRCompliant — DPA available, sub-processor list public, Art. 30 records maintained
Data residency (EU)Primary data plane (Supabase Postgres) hosted in EU (Frankfurt). Edge cache distributed across 300+ datacenters.
Encryption in transitTLS 1.3 minimum + HSTS preload
Encryption at restAES-256 (Supabase managed); OAuth tokens AES-GCM-encrypted in worker memory (key never reaches Postgres)
MFA for privileged rolesScaffold shipped R171 (enforcement after staging soak — MFA_ENFORCEMENT_MODE env-flag)
SSO/SAML for EnterpriseScaffold shipped R173 (tenant_sso_configs table + 503 route stubs; samlify wire-up R175+)
Tamper-evident audit logHash chain shipped R170-R174 (P39) — chain coverage 27/~37 callsites + chain-only DB trigger (warn mode)
Penetration testingFirst annual engagement scheduled R174 (external firm, $8-15k engagement). Summary published, full report under NDA.
SOC 2 Type 2In progress — observation window starts R200, audit completion mid-2026
ISO 27001Deferred — re-evaluation R200+ based on customer demand
CCPAReactive — implemented when first California customer signs
HIPAA / FedRAMPOut of scope — Preferium AI Edge is not pursuing healthcare/US government workloads in v1

Available artifacts (downloads)

ArtifactFormatNotes
Data Processing Agreement (DPA) templateMarkdown → PDF on deployGDPR Article 28-compliant. Customer fills in name/address/effective date and counter-signs.
Privacy PolicyMarkdown → HTMLPublic-facing privacy policy for Preferium.com properties.
Terms of ServiceMarkdown → HTMLMaster service agreement.
Vulnerability Disclosure Policy (VDP)Markdown → HTMLRFC 9116 safe-harbor + scope + SLA. Advertised via /.well-known/security.txt.
Sub-processor listMarkdown → HTMLMaintained per GDPR Art. 28(3). 30-day change notice per DPA.md §5.
GDPR Article 30 records of processingMarkdown → PDF on deployTemplate applies to Preferium AS as Processor; per-tenant extracts available on request.
Software Bill of Materials (SBOM)CycloneDX JSONGenerated by anchore/sbom-action (syft) + Sigstore-attested on every release tag. Obtain + verify at /sbom/.
Artifact attestationsSLSA L3 attestationsGenerated via GitHub Actions Attest-Build-Provenance on every release (R166).
Penetration test summaryPDFPublic summary. Full report under NDA — request via security@preferium.com. First engagement R174.
Status pageexternal (Better Stack)90 days uptime history + RSS subscription + email alerts.

Security disclosures


Sub-processors

Active list maintained at docs/legal/sub-processors.md. Subscribe to trust.preferium.com/changelog (RSS planned R175+) for change notifications.

Current count: 11 active sub-processors across 7 categories (primary infra / LLM providers / Google APIs / billing / email / SEO data / observability).


Compliance certifications

FrameworkStatusTarget dateNotes
SOC 2 Type 2Not started — preparation R170-R200, audit R200+Mid-2026Vanta or Drata for evidence automation + external CPA audit. 3-mo preparation + 3-mo observation.
ISO 27001Deferred — re-evaluation R200+ pending demandTBDMost NO/Nordic mid-market accepts SOC 2 alone. Broader ISMS than SOC 2.
GDPRCompliant ✅MaintainedDPA + sub-processor list + Art. 30 records + DPO + breach-notification process all in place.
CCPAReactive — implemented at first California customerWithin 30 days of needAdds CA-specific disclosures + opt-out flow to Privacy Policy.
HIPAAOut of scopeNeverNot pursuing healthcare.
FedRAMPOut of scopeNeverNot pursuing US federal.

Data Protection Officer

Per docs/legal/dpo-designation.md, the DPO role is currently held by Robert Andre Johansen (Founder/CEO Preferium AS). Robert is the primary contact for data-subject requests, supervisory authority communications, and Customer DPO-to-DPO escalations.

R174 records the long-term DPO arrangement (Option A: Robert; Option B: external DPO service; Option C: hybrid). Decision documented in docs/legal/dpo-designation.md.

Contact: dpo@preferium.com (alias to current DPO mailbox).


Incident response


Changelog

The changelog for trust artifacts (sub-processor changes, certification milestones, audit findings) will be published at trust.preferium.com/changelog post-R175 deploy with RSS subscription.

For now: see the change logs in sub-processors.md §J and gdpr-article-30-records.md §H.


Contact


Implementation status

R171 originally planned the full trust center deploy. R171-R174 progressed as follows: