Sample workspace
Cited drafts from a fictional policy pack — so you can see the shape of a fill before you buy.
Demo only. This is a static sample using fictional “Lumenfield” policies (not a live upload workspace yet).
Paid pilots and Free Friday fills are delivered DFY from your real docs. Self-serve upload app ships after first paid pilots.
1 source · 6 sample questions
Engine: heuristic stub (same shape as product)
Source: Lumenfield-Information-Security-Policy.md
A.1Cited
Is customer data encrypted at rest?
Yes. AES-256 for primary datastores and object storage; keys via cloud KMS.
Citation · §2 Encryption
“Data at rest in primary datastores and object storage is encrypted with AES-256.”
A.2Cited
Is data encrypted in transit?
Yes. TLS 1.2 or TLS 1.3 for customer data in transit.
Citation · §2 Encryption
“Customer data is encrypted in transit using TLS 1.2 or TLS 1.3.”
B.1Cited
Do you enforce MFA for workforce access?
Yes. MFA required via corporate IdP for workforce and privileged access.
Citation · §4 Access control
“Multi-factor authentication is required for all workforce and privileged access via the corporate identity provider.”
C.2Cited
Do you maintain an incident response / customer notification process?
Yes. Written IR plan with customer notification procedures.
Citation · §7 Incident response
“Lumenfield maintains a written incident response plan including customer notification procedures.”
J.1Needs review
Do you hold a current FedRAMP High authorization for the commercial SaaS tenant?
Needs review. No matching language in the uploaded sample policy — left blank rather than inventing a Yes.
No citation
Low-match questions stay Needs review instead of hallucinating compliance.
J.2Needs review
Is a formal customer uptime SLA defined in this policy document?
Needs review. Sample policy does not define a customer-facing uptime SLA.
No citation
Export still includes the row for human follow-up.