Standards Document v1.0

The Verification Matrix

The formal methodology behind every Lunara certification. Requirements, criteria, evidence, evaluation, and review triggers for each certification track, mapped to the seven constitutional pillars.

Published MMXXVI · August 2, 2026

Foundational Principles

PRINCIPLE I
Verification is not a blanket guarantee. A Lunara certification verifies the specific scope defined in the matrix. It does not certify safety, accuracy, ethics, security, performance, legality, or universal reliability. The verification record explicitly states what it does not cover.
PRINCIPLE II
Every verification follows a chain of reasoning. No verifier may move from initial impression to certification without passing through the full decision chain: Claim, Subject, Scope, Criteria, Evidence, Evaluation, Findings, Decision, Record.
PRINCIPLE III
Evidence quality is graded, not binary. Evidence is evaluated as direct, corroborating, declarative, or inferential. The matrix specifies which quality is sufficient for each criterion.
PRINCIPLE IV
Verification has a lifecycle. Certifications are issued with a validity period. Defined events trigger reassessment. Status changes are reflected in the public registry in real time. A certification is a living trust mechanism, not a permanent badge.
PRINCIPLE V
Proportionality applies to verification depth. Verification requirements scale with the risk profile and operational scale of the subject. A small business certification does not require the same evidence depth as an AI entity handling protected health data. Governance must be achievable at every scale.

The Verification Decision Chain

Claim Subject Scope Criteria Evidence Evaluation Findings Decision Record
Track I

Shield Certification

Constitutional governance certification for businesses operating or deploying AI systems. Verifies legal identity, domain ownership, and compliance with the seven pillars at a foundational level.

$80 initial · $149 annual renewal
PillarCriterionEvidence RequiredPassFail
I. Verified IdentityLegal registration of the business entity is confirmed and matches the declared nameLegal registration number + registration country (declarative, verified against public registry)Registration matches declared entity nameRegistration absent or name mismatch
I. Verified IdentityDomain ownership is confirmedDNS TXT token placed at declared domain (technical, direct evidence)Token verified at DNS levelToken absent or mismatched
I. Verified IdentityContact email is operational and controlled by the applicantApplication submitted from declared email; confirmation link clicked (direct)Email confirmed and reachableEmail bounces or unconfirmed
II. Declared GovernanceApplicant has a public website describing their operationsWebsite URL returns 200 with substantive content (technical, direct)Live website with real contentDead link, parked, or no content
III. TransparencyApplicant agrees to the Lunara Code of ConductCode of conduct agreement checkbox at application (declarative)Agreement recorded with timestampAgreement not provided
IV. Data SovereigntyNo public fraud flags or enforcement actions against the entityManual review: search public records, scam databases, regulatory alerts (corroborating)No flags found in public recordsActive fraud flags or enforcement
V. Audit AccessibilityApplication record is complete and reviewableAll form fields populated, reviewer notes recorded (documentary)Complete record with reviewer signoffIncomplete application
VI. RevocabilityApplicant understands certification can be revokedCode of conduct includes revocation acknowledgment (declarative)Acknowledgment presentAcknowledgment absent
VII. ProportionalityVerification depth is appropriate to entity scaleEntity type classification (business, startup, nonprofit) determines review depth (evaluative)Review matches entity typeReview insufficient for declared type
Track II

AI Entity Verification

Deep verification for autonomous AI agents and systems. Requires demonstrated governance framework, operational disclosure, human accountability chain, and audit readiness. The entity must show it operates under declared, auditable rules.

$899 initial · $499 annual renewal
PillarCriterionEvidence RequiredPassFail
I. Verified IdentityThe AI entity has a unique, declared identifier and an accountable owner organizationShield Certification of parent org (direct) + entity declaration form with system name, version, and scope (documentary)Parent org certified + entity declaredNo parent certification or entity undefined
II. Declared GovernanceA published governance framework specifying system scope, boundaries, human oversight, and incident response existsGovernance framework document (documentary, direct). Must cover: scope, boundaries, oversight protocol, incident response, review cadenceAll five framework components presentMissing components or framework absent
III. TransparencyThe AI entity discloses its nature when initiating contact with humansDisclosed interaction logs or system prompt declaration showing AI self identification (direct or corroborating)Disclosure mechanism demonstratedNo disclosure or misrepresentation found
IV. Data SovereigntyThe entity's data access and retention practices are documented and minimised to declared purposeData handling declaration (documentary) + technical configuration review if applicable (technical)Declaration matches operational scopeOverbroad data access or no declaration
V. Audit AccessibilityThe entity maintains logs or evidence trails auditable by independent partiesLog architecture documentation or sample audit trail (technical, direct). For scaled deployments: annual transparency report commitment (declarative)Audit trail exists and is accessibleNo logs or logs not reviewable
VI. RevocabilityRevocation protocol is defined: who can revoke, under what conditions, and how users are notifiedRevocation protocol document (documentary). Must define triggers, notification chain, and registry update processProtocol complete with notification chainProtocol absent or incomplete
VII. ProportionalityVerification depth scales with entity deployment scope (number of users, autonomous actions, risk profile)Deployment declaration with user count, action types, and risk tier (declarative). Higher risk triggers deeper review (evaluative)Review depth matches risk tierInsufficient review for declared risk
Track III

Strategic Registry Partner

For organizations embedding Lunara verification into their platform. Requires organizational Shield Certification, technical integration capability, revenue sharing agreement, and ongoing compliance monitoring. Partners carry the Lunara trust mark on their platform.

$2,599 initial · $999 annual renewal
PillarCriterionEvidence RequiredPassFail
I. Verified IdentityPartner organization holds active Shield CertificationExisting Shield record with verified status (direct, from registry)Active Shield in good standingNo Shield or Shield expired
I. Verified IdentityPartner domain verified for embed integrationDNS verification on embed domain (technical, direct)Domain verified for API embeddingDomain unverified
II. Declared GovernancePartner has defined how Lunara verification is surfaced in their platformIntegration specification document (documentary). Must describe placement, display rules, and user experienceSpec complete and approvedNo integration spec or unapproved
III. TransparencyPartner discloses Lunara verification status accurately, no misrepresentationReview of partner platform showing verification display (direct, observed). Manual testing of lookup flowAccurate display, no exaggerationMisrepresented or misleading display
IV. Data SovereigntyPartner handles API keys securely and does not expose Lunara credentialsTechnical review of API key storage and usage (technical). Security questionnaire (declarative)Keys stored server side, no exposureKeys exposed or insecure storage
V. Audit AccessibilityPartner maintains lookup logs and referral records for revenue reconciliationAPI usage logs available for audit (technical). Monthly referral reports (documentary)Logs accessible and reconcilableNo logs or logs inconsistent
VI. RevocabilityPartner agreement includes revocation terms for misuse, misrepresentation, or nonpaymentSigned partner agreement with revocation clauses (documentary, direct)Agreement signed with revocation termsAgreement absent or terms missing
VII. ProportionalityPartner tier and fee structure matches their scale and usagePartner type classification and expected lookup volume (declarative). Fee tier validated against usage projections (evaluative)Tier appropriate for scaleTier mismatched or volume undeclared

Evidence Quality Tiers

Every piece of evidence submitted or gathered during verification is classified by quality. The matrix specifies which tier is sufficient for each criterion. Higher stakes require higher quality evidence.

Direct Evidence
Evidence that directly demonstrates the criterion is met. DNS token verification, confirmed email clicks, observed behavior, live website responses.
Sufficient alone for any criterion unless the matrix specifies corroborating evidence.
Corroborating Evidence
Independent evidence that supports a claim made by the subject. Public registry matches, third party database lookups, external scam database checks.
Sufficient when combined with at least one declarative or direct evidence item for the same criterion.
Declarative Evidence
A statement or declaration made by the subject or responsible entity. Code of conduct agreement, data handling declaration, governance framework self report.
Sufficient for low risk criteria. Must be combined with corroborating or direct evidence for high risk criteria.
Inferential Evidence
Evidence from which a conclusion can reasonably be drawn without direct demonstration. Entity type classification informing review depth, deployment scale informing risk tier.
Never sufficient alone. Supports evaluative decisions made by the reviewer but cannot be the sole basis for a pass finding.

Verification Lifecycle

Pending
Application submitted, awaiting review
Under Review
Evidence being evaluated against criteria
Verified
All mandatory criteria satisfied
Suspended
Temporary withdrawal pending reassessment
Revoked
Certification permanently withdrawn
Expired
Validity elapsed without renewal

Reassessment Triggers

Material system modification — Significant change to the AI entity's architecture, capabilities, or deployment scope triggers review within 30 days.
Change of ownership — Acquisition, merger, or transfer of the certified organization triggers reassessment of identity and governance.
Change in declared capability — If the entity begins operating outside its declared scope, the certification must be reviewed for continued validity.
Discovery of misleading evidence — If evidence provided during initial verification is found to be false or misleading, certification moves to suspended immediately and revocation review begins.
Public complaint or fraud report — A substantiated complaint from a user, regulator, or third party triggers a review. Unsubstantiated reports are logged but do not trigger reassessment alone.
Failure to maintain requirements — If the subject no longer meets mandatory criteria (domain goes offline, registration lapses, email becomes nonfunctional), certification moves to suspended after 14 days.

Scope Limitation

A Lunara certification verifies that the subject meets the defined criteria within the stated scope at the time of evaluation. It does not certify safety, accuracy, ethics, security, performance, legality, merchantability, or universal reliability. Lunara Society is not liable for actions taken by certified entities after certification. The certification record is the authoritative source of what was verified, when, and within what limits.
Every verification record includes: subject, category, standard version, scope, status, verification ID, issue date, expiry date, and reviewer of record.
The public registry reflects current status in real time. A lapsed or revoked certification is immediately visible to all API consumers.