Compute
Compliance, contracts and what they prove
Which document settles which question, why a measured control is not a certification, and why a subprocessor's report never becomes Lithi's report or your compliance.
Start with the obligation
Name the duty you have to meet, the data category it covers, the operation you will run and the period you are reviewing. Then pick the narrowest document that answers it.
Reviews go wrong when a general architecture statement is asked to settle a specific contractual question. The two are different kinds of evidence.
What each document settles
| Document | What it settles | What it does not settle |
|---|---|---|
| Data Processing Addendum | Roles, processing instructions, security measures, retention and transfers | Whether your particular use is lawful |
| Terms of Service | The commercial relationship and each party's obligations | How any single operation behaves at runtime |
| Subprocessor register | Which third parties may process, and for what | That their assurance material is Lithi's |
| Compute help and support | How to raise an issue and what is safe to share | Any contractual commitment about response |
Your organization stays responsible for its legal basis, its notices, its instructions and its configuration.
A measured control is not a certification
Three things get confused, and keeping them apart is most of the work.
A measured control is a dated check of a named operation, in a named environment. It supports the cases it names and nothing else.
A formal certification is issued by an auditor against published criteria, with a scope, a period and exclusions. Lithi does not claim SOC 2 or ISO/IEC 27001 certification.
Eligibility for a regulated data class is a third question again, and it is settled below.
Lithi does not inherit a subprocessor's report
A provider may hold its own report or certificate for its own service. That material can support a review of that provider. It has to name the issuer, the date, the covered service, the criteria, the exclusions and a way to verify it.
It does not become Lithi's report, and it does not establish that your use is compliant. A legal framework is not a certification, and it does not transfer through a supplier.
Regulated data is refused, not conditioned
Compute refuses regulated and secret-bearing content, and refuses credential content, as classification outcomes rather than warnings.
So for those classes there is no eligibility to negotiate. The answer is that the work does not belong here, and the refusal you receive says so with a next action.
What to ask for
Ask for the smallest useful set. Name the product, the data category, the operation, the environment and the review period, and request evidence tied to exactly that.
Check the date and scope of everything you receive. A genuine provider report can still exclude the service path you are evaluating, and a recent control check can still lack a live environment test.