TrustDesk
Back to workspace

Lumen Analytics

On Track

qn-006 · Data & Analytics

Deal stage
New Logo
Deal value
$320,000
Questions
5
Received
May 28, 2026
Due
Jul 5, 2026 (34d)
AI & Model Governance · q-027

How does your platform use AI, and is customer data used to train models?

83confidence
Needs Review
Drafted response

AI features run under a documented governance program covering approved use cases and human oversight; customer data is not used to train shared or third-party foundation models without explicit consent.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived2/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Mapped evidence

Routed toLegal

Why this verdict

  • Capped at Needs Review: AI & Model Governance carries legal/privacy exposure and always requires human sign-off, regardless of the 83 confidence score.
  • Evidence Freshness is below target (2/4).
AI & Model Governance · q-028

What human oversight exists for AI-generated outputs?

64confidence
Needs Review
Drafted response

AI-generated outputs are subject to documented human oversight and evaluation as defined in the AI governance program.

Confidence factors

  • Control Match3/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived2/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language3/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse2/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity3/4weight ×1.0

    How standard and well-bounded the question is.

Mapped evidence

Routed toLegal

Why this verdict

  • Evidence Freshness is below target (2/4).
  • Answer Reuse is below target (2/4).
Privacy & Data Retention · q-029

Describe data retention for AI training datasets.

81confidence
Needs Review
Drafted response

Data used by AI features is retained only as long as necessary to provide the service or meet legal obligations, consistent with the data retention policy.

Confidence factors

  • Control Match3/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language3/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity3/4weight ×1.0

    How standard and well-bounded the question is.

Routed toPrivacy / Data Protection

Why this verdict

  • Capped at Needs Review: Privacy & Data Retention carries legal/privacy exposure and always requires human sign-off, regardless of the 81 confidence score.
Privacy & Data Retention · q-030

Are AI vendors and subprocessors disclosed?

47confidence
Escalate
Drafted response

A current subprocessor list, including AI vendors, is maintained and published; subprocessors are bound by data protection agreements.

Confidence factors

  • Control Match3/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived0/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language2/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse2/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity3/4weight ×1.0

    How standard and well-bounded the question is.

Routed toPrivacy / Data Protection

Why this verdict

  • Escalated: a sensitive Privacy & Data Retention question is grounded in expired evidence — it cannot be answered from the library as-is.
  • Approved Language is below target (2/4).
  • Answer Reuse is below target (2/4).
Encryption & Data Protection · q-031

What encryption protects data processed by AI features?

100confidence
Auto-Approved
Drafted response

Data processed by AI features is encrypted at rest using AES-256 across production data stores, consistent with the platform's encryption standards.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse4/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Mapped evidence

Routed toAuto-Approved

Why this verdict

  • Strong control match on current, approved evidence with no sensitivity flags — cleared to auto-approve.