Lunara Society

Enter your credentials to access the member area with full methodology, intelligence briefings, and governance guides.
Not yet a member? Obtain the Shield →
Member Dashboard
Shield Status
Checking...
Loading your verification status
Lunara ID
LUNA-7K2M-94RT
Permanent identifier · Revocable status
Machine-Readable Status
Available after certification
Registry Status
Not listed
Complete certification to appear here
Communication Policy
Not declared
Set during certification
Account
Member
Active account
Identity
What you tell us about yourself and your organisation. None of this is verified, it is your own description of yourself, and it carries no certification claim. Verifying that you control a domain is what Shield certification does.
Resized to 256 px in your browser before it is sent, which also strips the location data a phone camera writes into a photo. JPEG, PNG or WebP.
Registry
LIVE REGISTRY ENTRY lunarasociety.com/registry
{
"lunara_id": "LUNA-7K2M-94RT",
"entity_name": "Your Business",
"domain": "yourdomain.com",
"industry": "Your Industry",
"location": "Your Location",
"verification_status": "verified",
"shield_status": "active",
"registry_date": "2026-06-24",
"trust_tier": "founding_participant",
"ai_interaction_preference": "structured_inquiry_only",
"communication_policy": "declared"
}
Protection
Shield ID
Not yet issued
Issued after certification approval
Protection Level
Not certified
Start your application to begin
Status
Pending
Awaiting certification
Communication
Your communication policy is machine-readable and publicly accessible. AI systems and autonomous agents read this before attempting to contact your business.
Policy editing available in a future update. Contact maya@lunarasociety.com to request changes.
Reputation
Trust Score
Establishing
Grows with participation history
Verification Level
Verified
Identity confirmed
AI Preferences
Live preference editing coming in a future update. Contact maya@lunarasociety.com to adjust preferences.
Activity
History
Discovery
/llms.txt
Live ✓
Published to your domain
/ai.json
Live ✓
Published to your domain
/robots.txt
Updated ✓
AI crawlers welcomed
Registry Link
Active ✓
Queryable by AI systems
Controls
Governance
Intelligence
Member Exclusive
The full seven pillar assessment methodology used by Lunara reviewers. This is the implementation layer behind the public certification overview. Do not distribute outside your organization.
Verification steps:
Verification steps:
Verification steps:
Full methodology document available in the Audit Templates section. Each pillar includes:
Member Exclusive
Downloadable assessment templates used by Lunara reviewers. These templates operationalize the seven pillars into specific audit questions with scoring criteria.
12 point assessment covering legal registration, domain ownership, contact verification, and fraud screening.
18 point assessment covering policy completeness, human oversight, model documentation, and escalation procedures.
9 point assessment covering data boundary declaration, processing transparency, and retention policies.
7 point assessment covering audit log availability, oversight body access, and historical record retention.
6 point assessment covering public revocation mechanism, notification process, and registry update procedures.
10 point assessment covering risk classification, governance proportionality, and impact assessment requirements.
Member Exclusive
The full pillar by pillar mapping to specific regulatory requirements. This is the implementation detail behind the public certification spec pages. Use this to prepare your organization for certification or to understand compliance gaps.
| Pillar I | HIPAA Security Rule 164.308(a)(4) Access Management |
| Pillar II | FDA Predetermined Change Control Plan (PCCP) |
| Pillar III | HIPAA Privacy Rule 164.530 Notice Requirements |
| Pillar IV | HIPAA 164.314 Business Associate Data Boundaries |
| Pillar V | Joint Commission IM.02.01.03 Information Audit |
| Pillar VI | EU AI Act Annex III High Risk Revocation |
| Pillar VII | FDA Risk Categorization 21 CFR 820.30 |
| Pillar I | FINRA Rule 2090 Know Your Customer |
| Pillar II | SR 11-7 Model Risk Management Framework |
| Pillar III | CFPB Reg Z 226.47 Disclosure Requirements |
| Pillar IV | GLBA 501.15 Data Security and Boundary Rules |
| Pillar V | Basel Pillar 2 Audit and Disclosure |
| Pillar VI | EU AI Act Credit Scoring Revocation Rights |
| Pillar VII | NAIC Model Governance Risk Proportionality |
| Pillar I | FISMA 800-53 IA-2 Identity Verification |
| Pillar II | NIST AI RMF Govern Function |
| Pillar III | EO 14110 Transparency Reporting |
| Pillar IV | FedRAMP Data Boundary Controls |
| Pillar V | GAO Audit Readiness Standards |
| Pillar VI | FAR Contract Termination and Revocation |
| Pillar VII | Title VI and Section 508 Proportionality |
Member Exclusive
Competitive intelligence and market analysis curated by the Lunara Society intelligence team. Updated weekly. These briefings inform our certification standards and help members understand the governance landscape.
From August 2026 every claim in these briefings carries its provenance. Verified means checked against a primary source. Reported means received from the intelligence desk and not yet confirmed. Nothing is promoted from one to the other without the source being recorded.
NewCore emerged from stealth with $66M for identity architecture spanning humans, machines, and AI agents. Hush raised a $30M Series A with Akamai as strategic backer. Okta is expanding runtime agent security and moving on Permiso. SailPoint's Agentic Fabric now unifies human, non-human, and AI agent identity. Strategic implication: four vendors are converging on the same primitives, identity, permissions, lifecycle, runtime enforcement. Consolidation at the control plane leaves interpretation unclaimed. None of these tools tells an executive which obligation applies to a given agent, who owns that obligation, or what evidence would be produced if a regulator asked. A control that passed is not an obligation that holds.
PROVENANCE: SOURCED
Every claim above now carries the primary announcement it came from. Each link goes to the issuing company or the outlet that broke it, so a reader can check the wording themselves rather than take ours.
One caveat we would rather state than bury: the Okta line is reported deal activity, and the parties have described its stage differently over the weeks since. We have kept our own wording at the cautious end until Okta says otherwise in its own filings.
SailPoint acquired Entro Security for NHI discovery. ServiceNow invested $40M in BusinessNext for vertical governance. Okta expanded Cross App Access to 25+ ISV partners. Tailscale launched Aperture for shadow AI discovery (alpha). Strategic implication: horizontal governance is consolidating. Vertical specialization is the only defensible position.
OpenAI launched Presence with built in governance. Anthropic published CISA alignment. Google added governance controls to Vertex AI. Risk: model providers are bundling governance into their platforms. Opportunity: constitutional authority position remains unclaimed. No competitor owns the institutional standard.
Delve, a centralized AI certification firm, collapsed due to inherent conflicts in centralized compliance models. Analysis: centralized certifiers cannot maintain neutrality when their revenue depends on the entities they certify. Lunara's decentralized constitutional model avoids this through public registry transparency and revocability.
68% of enterprises plan to switch AI vendors within 12 months. This creates a governance vacuum: vendor-specific compliance does not persist across transitions. The vendor transition governance checkpoint is Lunara's key innovation. The standard persists even when the implementation changes.
Member Exclusive
The implementation guide for the vendor transition governance checkpoint. This is Lunara's key differentiator and the primary use case for enterprise certification.
When an enterprise switches from one AI vendor to another, the governance framework built for the first vendor does not transfer. Security configurations, audit logs, compliance mappings, and oversight mechanisms all need to be rebuilt. This creates a governance gap during transition that can last weeks or months.
The constitutional governance framework is vendor neutral. It operates at the institutional layer, not the implementation layer. When an enterprise switches vendors:
The vendor shall maintain Lunara Constitutional AI Governance Certification throughout the term of this agreement. In the event of vendor transition, the certification shall persist through the institutional governance framework rather than the vendor specific implementation. The vendor shall support delta assessment within 72 hours of transition notification and maintain audit continuity through the public Lunara Registry.