> ## Documentation Index
>
> Fetch the complete documentation index at: https://lithi.ai/llms.txt
>
> Use this file to discover all available pages before exploring further.

---
title: "Compliance and assurance"
description: "Understand how Lithi contracts, product controls, tests, and provider reports support a scoped compliance review, and how to report an accessibility barrier."
route: "/trust/compliance"
page_id: "trust-compliance"
last_updated: "2026-09-03"
reading_time: "5 min read"
audience: "Security reviewers, IT leads, procurement, and legal teams"
voice: A
source_locale: en-US
source_status: APPROVED
source_version: "trust-compliance-en-us-2026-09-03-fifteen-route-v1"
robots: noindex
---

# Compliance and assurance

Lithi supports a compliance review with contracts, product controls, focused tests, and provider materials. These sources answer different questions. They do not create a Lithi certification or decide your organization's legal obligations for you.

## Start with the obligation

Name the framework or contract duty, data class, operation, customer role, environment, and review period. Then choose the narrowest source that addresses that question. Use the [Privacy Policy](/legal/privacy) and [Data Processing Addendum](/legal/dpa) for terms, roles, instructions, security measures, retention, transfers, and related duties.

Your organization remains responsible for its legal basis, notices, instructions, configuration, and decisions. Lithi can explain product boundaries and available review material, but it cannot provide a legal conclusion for your organization.

## Separate contracts, product controls, and tests

Contracts allocate responsibilities and describe agreed protections. Product controls describe scoped permissions, customer-managed boundaries, human decisions, and provider separation. A contract is not a runtime log. A control description is not proof that every customer selected the same setting.

Focused tests can check a named content or structural condition. They do not test every runtime behavior, tenant configuration, provider path, or customer data class. Ask for the environment, operation, date, and scope when your conclusion depends on a live condition.

## Review provider reports carefully

A provider may publish a report or certification for its own service. That material can support a provider-specific review when it identifies the issuer, report or certificate date, covered service, criteria, exclusions, review period, and verification link.

Lithi does not claim SOC 2 or ISO/IEC 27001 certification. GDPR is a legal framework, not a certification that transfers through a provider. A provider's SOC 2, ISO/IEC 27001, HIPAA, PCI DSS, or GDPR material remains provider-specific. It does not become Lithi's certification or establish that your use is compliant.

## Choose the evidence you need

Start with the decision, not with a large document bundle. Ask for the smallest useful set. For example, a review of Compute security boundaries may need the [Compute security](/trust/security) page, the [encryption evidence](/trust/encryption) page, and a current environment-specific check. A review of contractual duties belongs with the DPA and your agreement.

Check the review date, product version, environment, and operation covered by each item. A recent source review can still lack an environment check. A provider report can remain genuine while excluding the service or data path you are evaluating. Keep conclusions narrow: a passing check supports the cases it names, not an untested configuration or data class.

## Accessibility

Lithi aims to make its public pages and product controls operable for people with different access needs, including keyboard use, readable text and contrast, clear labels, reduced motion, and assistive-technology support. This page does not claim complete conformance, a fixed audit schedule, or a guaranteed repair time.

To report a barrier, name the page or product surface you used, what you tried to do, and which browser, device, or assistive technology was involved. Share the minimum context needed to reproduce the problem; do not include credentials, private customer content, payment details, identity documents, or unrelated personal data.

## Keep conclusions scoped

Mark a question open when its source lacks an issuer, date, scope, environment, period, exclusion, or verification link. Request updated material after a material product, provider, configuration, or obligation change. Do not fill a gap with a badge, inherited statement, or undated summary. Keep each conclusion beside the source that supports it and the limit that qualifies it.

## What this review covers

| Field | Record |
|---|---|
| Scope | A named obligation, Lithi product, control, environment, evidence period, or accessibility report. |
| Status | Review-specific; no certification or universal conformity is established here. |
| Owner | Lithi trust team |
| Evidence | Applicable contract, control record, dated test, independent report, or accessibility review. |
| Last reviewed | 2026-09-03 |
| Limitation | Supplier evidence and authored policy do not establish Lithi-wide compliance or conformance. |

## Primary action

[Review the Data Processing Addendum](/legal/dpa) for contractual processing terms, then contact us with any scope that needs clarification.

## Related links

- [Review Compute security](/trust/security)
- [Review subprocessors](/trust/subprocessors)
- [Report an accessibility barrier](/contact)
