Skip to content
LUNTA

For procurement

The commercial terms and the assurance status, in one document you can file.

What a procurement function needs in one place before a business sponsor is allowed to sign: how an engagement is priced and contracted, what we will send you on request, which assurances we hold, which we do not, where the system runs, and how you leave.

This is a consolidation, not a new document. Every line below is already published in full on the engagements and security pages, those pages remain the authority, and nothing has been made stronger on the way here. Where a term is shortened, the full statement is one link away.

This page is built to print. Use your browser’s print or save-as-PDF and it files as one document — there is no form in front of it and no gated version of it anywhere else.

The engagement shape, in eight lines

The commercial and contractual position, compressed. Each line is the short form of a published term — the reasoning behind it, and the terms not listed here, are on the engagements page.

Delivery is priced one phase at a time
Each phase is priced against the gate it has to clear, so the commercial unit and the evidence unit are the same size. You buy a phase, not a programme with that phase at the front of it.
The diagnosis is fixed-scope and fixed-fee
Price, dates, and deliverables are known before you commit, and the diagnosis is sold as a complete thing rather than as a qualification exercise for a larger programme.
Gate criteria are a schedule to the contract
The thresholds a phase must clear are annexed to the statement of work and signed before the work starts, with the consequence of missing them written into the same document.
Termination for convenience at every gate
You can end the engagement at any gate, without cause and without an exit fee.
You own what we make
Deliverables, code, evaluation suites, and documentation are yours on payment. We retain our pre-existing methods and tooling, and grant you a licence to use anything of ours that ends up embedded in your deliverables.
Confidentiality runs both ways, and publicity is opt-in
A mutual NDA before material information is exchanged, and our default is that the engagement stays confidential — no logo, no case study, no anonymised retelling — unless you affirmatively ask for it.
Subcontracting is named or it does not happen
We do not put a party you have not been told about onto your engagement. Where specialist help is the right answer, you are told who, why, and on what terms before they start.
Liability, insurance, and audit are negotiated, not deflected
We expect these clauses to be discussed properly. Where a requirement is disproportionate to the engagement, we say so and explain why rather than signing it and hoping it is never exercised.

The commercial and contract terms in full

What you can ask us for

All of it available on request, most of it before you have committed to anything. If something on your framework’s list is missing here, ask — the answer will be what we hold, not what we intend to hold.

  • Company registration and tax details
  • Evidence of insurance to the levels your policy requires
  • A signed data processing agreement and named sub-processor list
  • Security questionnaire responses in your format, with named owners
  • Sample master agreement and statement of work, including the gate schedule
  • Conflict-of-interest declaration covering adjacent work
  • References, spoken rather than written, where the referee has agreed to speak — we ask, we never assume, and we will tell you plainly where we do not yet have one for work like yours
  • Supplier policy statements your framework requires, with a plain answer on which we hold and which we do not

Assurances we do not hold are published rather than deflected — the full list, including the certifications we lack, is on the security page.

See the assurance status

Assurance status — including what we do not hold

Most supplier pages list what they have. The useful half is what they do not, so both halves are here. If your policy requires an assurance marked “Not held”, we are not a supplier you can use today — and you should find that out on this page rather than in week three of a procurement cycle.

Assurances LUNTA holds, does not hold, or provides on request
ISO/IEC 27001 certificationNot heldWe are a young practice and hold no certification. We will publish a target date here when one is committed, and not before — a roadmap date nobody is accountable for is exactly the kind of claim this site exists to avoid.
SOC 2 Type II reportNot heldSame position. If your framework treats it as mandatory rather than preferred, tell us on the first call and we will say so plainly instead of proposing a workaround.
Security questionnaire responsesOn requestWe complete yours, in your format, with named owners against each answer. We do not maintain a pre-baked answer pack, because the honest answer usually depends on the deployment shape you choose above.
Data processing agreementBefore processingExecuted before any personal data is processed. Yours or ours, with sub-processors and processing locations named in it.
Named sub-processor listOn requestProvided at contracting and kept current, with advance notice of changes and a right to object written into the agreement.
Professional indemnity and cyber insuranceAt contractingLevels are agreed at contracting against your requirement, and certificates are provided before work starts rather than after a claim.
Penetration testing of delivered systemsPer engagementCommissioned or coordinated where the scope warrants it, as a named line in the statement of work. We do not carry it as a standing claim about work we have not done yet.
Right to auditNegotiatedWe accept audit and records-access terms proportionate to the engagement. We will tell you where a clause is disproportionate rather than signing and hoping it never gets exercised.

Where the system runs

Three shapes, in order of preference. Each is stated with its real trade-off, because the fastest option to start is not the one that survives a security review.

01 · In your tenant — the default
Your cloud, your identity provider, your logging, our engineers as named and time-boxed guests. You hold the keys and can revoke us in an afternoon. Slowest to start, and the only shape where the exit conversation is trivial.
02 · Your cloud, operated by us
You own the accounts and the data; we hold scoped operational access to run the system while your team takes it over. Suitable when your platform team has no capacity in the phase window. Access scope and its expiry are named in the statement of work.
03 · A dedicated environment we operate
Used only where you genuinely cannot host, and only under a written exception that names a migration date back into your estate. We will tell you what you are giving up: your logging, your key management, and a one-step revocation.

How you leave

At any gate, without cause and without an exit fee. What you keep is the same whether you leave at the first gate or the last: every artifact produced to that point, the code and evaluation suites in your repositories, infrastructure in your accounts, and a handover pack written for your engineers. In the default deployment shape that is already true on the day you go — your accounts, your repositories, your keys, nothing held only by us. Where you contracted the written exception of an environment we operate, the handover pack names every credential and configuration that transfers and the date it does, which is the migration date that exception had to carry before the work started.

The full exit terms, with the reasoning

If one of these lines decides your answer, tell us on the first call.

We would rather lose a procurement early, on a term we do not meet, than late on one we were never going to meet. Send us the questionnaire, the framework requirement, or the clause — you will get a plain answer, including where the answer is no.

Last reviewed July 2026.