The formal methodology behind every Lunara certification. Requirements, criteria, evidence, evaluation, and review triggers for each certification track, mapped to the seven constitutional pillars.
Constitutional governance certification for businesses operating or deploying AI systems. Verifies legal identity, domain ownership, and compliance with the seven pillars at a foundational level.
| Pillar | Criterion | Evidence Required | Pass | Fail |
|---|---|---|---|---|
| I. Verified Identity | Legal registration of the business entity is confirmed and matches the declared name | Legal registration number + registration country (declarative, verified against public registry) | Registration matches declared entity name | Registration absent or name mismatch |
| I. Verified Identity | Domain ownership is confirmed | DNS TXT token placed at declared domain (technical, direct evidence) | Token verified at DNS level | Token absent or mismatched |
| I. Verified Identity | Contact email is operational and controlled by the applicant | Application submitted from declared email; confirmation link clicked (direct) | Email confirmed and reachable | Email bounces or unconfirmed |
| II. Declared Governance | Applicant has a public website describing their operations | Website URL returns 200 with substantive content (technical, direct) | Live website with real content | Dead link, parked, or no content |
| III. Transparency | Applicant agrees to the Lunara Code of Conduct | Code of conduct agreement checkbox at application (declarative) | Agreement recorded with timestamp | Agreement not provided |
| IV. Data Sovereignty | No public fraud flags or enforcement actions against the entity | Manual review: search public records, scam databases, regulatory alerts (corroborating) | No flags found in public records | Active fraud flags or enforcement |
| V. Audit Accessibility | Application record is complete and reviewable | All form fields populated, reviewer notes recorded (documentary) | Complete record with reviewer signoff | Incomplete application |
| VI. Revocability | Applicant understands certification can be revoked | Code of conduct includes revocation acknowledgment (declarative) | Acknowledgment present | Acknowledgment absent |
| VII. Proportionality | Verification depth is appropriate to entity scale | Entity type classification (business, startup, nonprofit) determines review depth (evaluative) | Review matches entity type | Review insufficient for declared type |
Deep verification for autonomous AI agents and systems. Requires demonstrated governance framework, operational disclosure, human accountability chain, and audit readiness. The entity must show it operates under declared, auditable rules.
| Pillar | Criterion | Evidence Required | Pass | Fail |
|---|---|---|---|---|
| I. Verified Identity | The AI entity has a unique, declared identifier and an accountable owner organization | Shield Certification of parent org (direct) + entity declaration form with system name, version, and scope (documentary) | Parent org certified + entity declared | No parent certification or entity undefined |
| II. Declared Governance | A published governance framework specifying system scope, boundaries, human oversight, and incident response exists | Governance framework document (documentary, direct). Must cover: scope, boundaries, oversight protocol, incident response, review cadence | All five framework components present | Missing components or framework absent |
| III. Transparency | The AI entity discloses its nature when initiating contact with humans | Disclosed interaction logs or system prompt declaration showing AI self identification (direct or corroborating) | Disclosure mechanism demonstrated | No disclosure or misrepresentation found |
| IV. Data Sovereignty | The entity's data access and retention practices are documented and minimised to declared purpose | Data handling declaration (documentary) + technical configuration review if applicable (technical) | Declaration matches operational scope | Overbroad data access or no declaration |
| V. Audit Accessibility | The entity maintains logs or evidence trails auditable by independent parties | Log architecture documentation or sample audit trail (technical, direct). For scaled deployments: annual transparency report commitment (declarative) | Audit trail exists and is accessible | No logs or logs not reviewable |
| VI. Revocability | Revocation protocol is defined: who can revoke, under what conditions, and how users are notified | Revocation protocol document (documentary). Must define triggers, notification chain, and registry update process | Protocol complete with notification chain | Protocol absent or incomplete |
| VII. Proportionality | Verification depth scales with entity deployment scope (number of users, autonomous actions, risk profile) | Deployment declaration with user count, action types, and risk tier (declarative). Higher risk triggers deeper review (evaluative) | Review depth matches risk tier | Insufficient review for declared risk |
For organizations embedding Lunara verification into their platform. Requires organizational Shield Certification, technical integration capability, revenue sharing agreement, and ongoing compliance monitoring. Partners carry the Lunara trust mark on their platform.
| Pillar | Criterion | Evidence Required | Pass | Fail |
|---|---|---|---|---|
| I. Verified Identity | Partner organization holds active Shield Certification | Existing Shield record with verified status (direct, from registry) | Active Shield in good standing | No Shield or Shield expired |
| I. Verified Identity | Partner domain verified for embed integration | DNS verification on embed domain (technical, direct) | Domain verified for API embedding | Domain unverified |
| II. Declared Governance | Partner has defined how Lunara verification is surfaced in their platform | Integration specification document (documentary). Must describe placement, display rules, and user experience | Spec complete and approved | No integration spec or unapproved |
| III. Transparency | Partner discloses Lunara verification status accurately, no misrepresentation | Review of partner platform showing verification display (direct, observed). Manual testing of lookup flow | Accurate display, no exaggeration | Misrepresented or misleading display |
| IV. Data Sovereignty | Partner handles API keys securely and does not expose Lunara credentials | Technical review of API key storage and usage (technical). Security questionnaire (declarative) | Keys stored server side, no exposure | Keys exposed or insecure storage |
| V. Audit Accessibility | Partner maintains lookup logs and referral records for revenue reconciliation | API usage logs available for audit (technical). Monthly referral reports (documentary) | Logs accessible and reconcilable | No logs or logs inconsistent |
| VI. Revocability | Partner agreement includes revocation terms for misuse, misrepresentation, or nonpayment | Signed partner agreement with revocation clauses (documentary, direct) | Agreement signed with revocation terms | Agreement absent or terms missing |
| VII. Proportionality | Partner tier and fee structure matches their scale and usage | Partner type classification and expected lookup volume (declarative). Fee tier validated against usage projections (evaluative) | Tier appropriate for scale | Tier mismatched or volume undeclared |
Every piece of evidence submitted or gathered during verification is classified by quality. The matrix specifies which tier is sufficient for each criterion. Higher stakes require higher quality evidence.