Independent failure domain — served separately from api.preferium.com.

Preferium AI Edge — Trust Center

Customer-facing trust surface, served live at https://trust.preferium.com. This file is the canonical content source — the Astro static Worker (apps/trust/) imports it directly and runs as an independent failure domain with no Supabase, KV or AI Gateway binding.


Control status

Every row below is generated from the control registry in packages/shared/src/trust-controls.ts and checked by node scripts/check-trust-controls.mjs. Nothing here is a certification, and nothing here is a plan presented as a fact.

A control is Active only when three separate things are true: the code is implemented, its behaviour is tested, and its configuration has been read back in the environment it protects. Source code that exists is not a configuration that was verified. Anything short of all three is Limited, even when the implementation is complete — which is why every runtime control on this page reads Limited today. Planned means the work has not been done at all.

Control evidence observed: 2026-09-11 · Next review due: 2026-12-10 · Control owner: Robert André Johansen (post@preferium.no)

Control Status What is actually true today
GDPR-FRAMEWORK-001 Limited the contractual framework is published: DPA, subprocessor register and Article 30 records. The operational controls behind them have not been audited by anyone outside Preferium.
DATA-RESIDENCY-EU-001 Limited the primary data plane is configured for a Supabase EU region, and edge delivery is global by design. We publish no provider readback proving where every byte sat on a given day.
ENCRYPTION-001 Limited TLS with HSTS is set on every response by shared header code under test, and integration tokens are encrypted before storage. Encryption at rest is provider-managed and taken on the provider contract, not measured by us.
MFA-PRIVILEGED-001 Limited the privileged-role gate is implemented and unit-tested, and an unset or invalid mode resolves to the fail-closed default in production. We have not read back a production configuration or a privileged-user enrolment, so we do not claim multi-factor authentication is in force.
SSO-SAML-001 Limited SAML 2.0 SP-initiated login with IdP metadata and InResponseTo binding is implemented, plan-gated and unit-tested. No customer identity provider has been configured end to end, so Enterprise single sign-on is not yet in service.
AUDIT-CHAIN-001 Limited sensitive actions append to a hash-chained audit log whose chain integrity is enforced by a database trigger, and repository guards keep the coverage honest. No external party has verified a production chain.
BACKUP-CAPTURE-001 Limited Read-only production observation on 2026-09-19 found 115 completed legacy backup-run records (last 2026-09-16), but no active replacement capture snapshot/epoch/chain, capture outcome or export snapshots. Legacy records do not verify retained object completeness or restorability. No signed, witnessed production capture is evidenced. Managed backup/PITR configuration is unknown because the observer lacks a least-privileged backups_read credential. Local fixture artifacts do not prove independent provider copies.
BACKUP-RESTORE-001 Limited the restore path was rehearsed end to end on 2026-09-11 against disposable local databases and in-memory buckets: 49 probes passed and crash-and-resume converged exactly once. It has never run against a provider, and the local duration is not a recovery time objective.
DR-RESIDUAL-001 Limited total loss of the managed database, authentication and point-in-time-recovery domain is UNRECOVERABLE for complete authentication even if Cloudflare and R2 survive. What our own capture can replay is object metadata, which is a partial recovery of public and object state, not a managed whole-database recovery. This residual is tracked as DR-RESIDUAL-001 and stays limited until an independently administered encrypted authentication export and import leg is built and rehearsed.
RECOVERY-OBJECTIVES-001 Limited Declared targets remain 300 s for managed database/authentication PITR, 3600 s for consistent database/customer objects and open money/provider/citation/route state, and 86400 s for forensic history. A recovery point objective is measured as observation time minus the time actually captured through, never as the age of a successful manifest. Observed production recovery points and recovery times remain unknown rather than met: no verified captured-through frontier or provider restore proves them. A completed legacy run or local fixture duration does not establish an achieved objective.
STATUS-PAGE-001 Limited status.preferium.com is a self-hosted worker in its own failure domain that renders the live health aggregate and says so when it cannot reach it. It stores no history, publishes no feed and sends no notifications. We use no third-party status-page product and offer no subscription of any kind.
SBOM-PROVENANCE-001 Limited the CycloneDX SBOM and signed build-provenance workflow is committed, but it triggers only on a release tag and no tag has been cut. Nothing has been generated, signed or published, so there is no artifact to download and no attestation to verify.
CCPA-001 Limited service-provider and contractor duties are covered in the DPA and Privacy Notice. Applicability and request handling are assessed per customer and per data flow rather than certified.
PENTEST-EXTERNAL-001 Planned no external penetration test has been performed. The first engagement is in vendor selection and no summary exists. We will publish one when a test has actually happened.
SOC2-TYPE2-001 Planned not started. Evidence automation is not contracted, no observation window has begun and no date is set. A target date appears here when an engagement is signed.

Not in scope

These are not controls and are not on a roadmap. We say so rather than leaving an empty row that reads like work in progress.


Available artifacts (downloads)

Artifact Format Notes
Data Processing Agreement (DPA) Published on preferium.com Article 28 contract intended for incorporation by signed Order, separate signature or evidenced authorised Dashboard acceptance; a counter-signed copy is available on request.
Privacy Notice Published on preferium.com Public-facing privacy notice for Preferium.com properties and the Service.
Service Terms Published on preferium.com Core B2B terms for every plan, supplemented by the Order, Agency Addendum, DPA, AUP and expressly incorporated schedules under the stated order of precedence.
Vulnerability Disclosure Policy (VDP) Markdown → HTML RFC 9116 safe-harbor, scope and response targets, advertised via /.well-known/security.txt. Published as a draft pending legal review — the safe-harbor commitment in §3 is offered as written.
Subprocessor register Published on preferium.com Maintained for GDPR Art. 28. 30-day change notice and objection process under the DPA §6.
GDPR Article 30 records of processing Markdown → PDF on deploy Records identified controller and processor activities; relevant extracts are available on request.
Software Bill of Materials (SBOM) CycloneDX JSON Nothing to download. The pipeline is committed but has never run — see SBOM-PROVENANCE-001 above and /sbom/. Request the current dependency inventory by email instead.
Artifact attestations SLSA provenance Nothing to download. Same pipeline, same reason. Details at /sbom/.
Penetration test summary PDF Does not exist — no test has been performed. See PENTEST-EXTERNAL-001 above.
Status page self-hosted worker The current health of the platform services, read live. It stores no history and sends nothing — see STATUS-PAGE-001 above.

Security disclosures


Sub-processors

The active register, with each provider’s purpose, location and transfer basis, is published at preferium.com/subprocessors — the only canonical copy; this trust centre does not repeat it. Changes are announced there with a 30-day notice per the DPA.


Privacy Contact and DPO assessment

Preferium AS has not appointed a Data Protection Officer under GDPR Article 37. The current assessment is recorded in docs/legal/dpo-designation.md and must be revisited if the scale, nature or legal classification of processing changes.

Robert André Johansen is the operational Privacy Contact. As founder and chief executive he is not represented as an independent DPO. Privacy requests and supervisory-authority communications use the public legal/privacy contact below.

Contact: post@preferium.no.


Incident response


Changelog

There is no changelog page and no subscription mechanism. Sub-processor changes are announced on preferium.com/subprocessors with 30 days’ notice per the DPA, and the change log in gdpr-article-30-records.md §H records what changed and when.


Contact