Home/About/Liability Assurance

Liability Assurance

Liability Assurance

Insurance, screening, data handling and delivery capacity — stated before you have to ask for it.

Every engagement puts someone from outside your organization close to systems you remain accountable for. This page states what carries that risk: the insurance held, how engineers are screened, who holds your credentials, what happens to your data, and the capacity behind the guarantees made elsewhere on this site.

It exists so that the questions procurement asks in week three are answered in week one. Nothing here is held back for a later conversation, and nothing here is a certification we do not hold.

What is actually covered if something goes wrong

Insurance

Lumensoft Networks carries commercial insurance written by The Hartford, at the limits below. Certificates are issued on request, and we name a client as additional insured where the contract requires it.

CoverageLimit
Commercial General LiabilityPer occurrence $1,000,000 · Aggregate $2,000,000
Commercial Automobile LiabilityOwned, hired and non-owned · Per occurrence $1,000,000
Employer's LiabilityPer accident $1,000,000 · Per employee for disease $1,000,000 · Aggregate disease $1,000,000
Professional Liability / Errors and OmissionsPer occurrence $5,000,000 · Annual aggregate $5,000,000
Crime (third-party indemnity), Surety or FidelityPer occurrence $3,000,000
Privacy and Security (Cyber) LiabilityPer occurrence $3,000,000 · Aggregate $3,000,000
Workers' CompensationIn compliance in the state of incorporation

Two of those lines matter more than the rest in this work. Professional Liability and Errors and Omissions, at $5,000,000 per occurrence, covers the advice — an architecture recommendation that turns out to be wrong. Privacy and Security (Cyber) Liability, at $3,000,000, covers what happens if data is exposed while we are inside your environment.

Those are the two figures worth checking, and they are the two most firms of this size do not carry. A vendor insured only for General Liability is covered against someone tripping in its office and against nothing that could actually happen on your network.

Screened before placement, and to your standard where yours is higher

Background screening

Co-Managed engineers are background screened before placement: criminal record, employment verification and drug screening. Where your own standard is more demanding than ours — and in regulated environments it usually is — we screen to your standard rather than asking you to accept ours, and evidence of screening is provided before the engineer starts.

You issue the credentials. You revoke them.

Credentials and access

A Co-Managed engineer works on your credentials, not ours. You generate the login and pass it to the named engineer. It is not shared with anyone else at Lumensoft and it is not held in a shared vault on our side.

Before starting, the engineer signs your access agreement and works to your access policy — not a Lumensoft policy applied to your network. That distinction matters more than it sounds: it means your existing controls, logging and review cycles cover the engagement without modification.

When the engagement ends, you disable the account. Access ends in that one action, on your side, without waiting for anything from us.

Work product lives in your systems

Your data

Documentation, configurations and design artefacts are produced into your database or your cloud instance, and that is where they stay. Lumensoft retains no working copies.

The single exception is encrypted backup held for restoration — disaster-recovery support, not a second copy of your estate kept for our convenience. It is encrypted, it is not accessed in the ordinary course of an engagement, and it exists so that a failure on your side is recoverable rather than final.

Compliance is a state of your environment, not a certificate we hand you

Regulated environments

No vendor can transfer your compliance obligation to itself, and any vendor offering to is describing something that does not exist. What we can state is which regimes we design and support within.

In healthcare, HIPAA-governed environments and HL7 and FHIR interfaces. In payments, PCI-DSS scope, including how recorded calls are handled in contact-centre design, which is where PCI scope quietly expands. In voice and emergency calling, Kari's Law, RAY BAUM'S Act §506, E.164 numbering and encrypted voice transport.

Where an engagement touches protected health information, we sign a Business Associate Agreement on request.

Frameworks, stated as frameworks

Method and governance standards

Assessment and architecture work is structured against established frameworks rather than a house methodology invented for the purpose. The NIST Risk Management Framework governs how risk is identified and ranked. TOGAF® governs the artefacts an architecture engagement produces, and the Zachman Framework governs how those artefacts are organized. ITIL® governs change and incident management on managed engagements. Governance, risk and compliance alignment runs across all three service lines.

These are methodologies, not attestations, and the distinction is deliberate. We do not claim a certification we do not hold, and you should treat any vendor that blurs that line as having told you something useful about itself.

No engagement depends on one person

Delivery capacity

The practice carries more than one Solution Architect, alongside technical recruiters, network engineers, service desk leads and helpdesk agents. Solution Architect work is assigned rather than owned. If the architect on your engagement becomes unavailable, another takes it — working from the same written assessment rather than from memory.

That is the practical reason the assessment is written down. A verbal handover between architects loses the reasoning and keeps only the conclusion, which is the part least worth keeping.

Why a seven-day shortlist is possible at all

The sourcing pipeline

A seven-day shortlist is only credible if the pipeline exists before the requirement does. Ours is maintained continuously rather than assembled per role, through technical schools and networking academies, job portals, and direct headhunting by our own technical recruiters.

Recruiters source and schedule. A practicing Solution Architect conducts the technical interview. A candidate becomes Solution Architect Validated™ only after that interview — reach is not validation, and a database of profiles is not a screened shortlist. We keep those two things separate in our language because they are separate in fact.

Common questions

Frequently asked questions.

Can you provide a certificate of insurance?

Yes, on request, and we name a client as additional insured where the contract requires it. The lines carried are General Liability, Commercial Automobile, Employer's Liability, Professional Liability and Errors and Omissions, Crime and Fidelity, Privacy and Security (Cyber) Liability, and Workers' Compensation.

Are your engineers background checked?

Yes. Co-Managed engineers are screened for criminal record, employment history and drugs before placement. Where your own screening standard is higher, we screen to yours and provide evidence before the start date.

Are you SOC 2 certified?

No, and we will not imply otherwise. Our assessment and architecture work is structured against the NIST Risk Management Framework, TOGAF®, the Zachman Framework and ITIL®. Those are methodologies rather than attestations, and we state them as such.

Will you sign a Business Associate Agreement?

Yes, on request, where an engagement touches protected health information.

Who holds the credentials a Co-Managed engineer uses?

You do. You generate the login and pass it to the named engineer. It is not shared with anyone else at Lumensoft. When the engagement ends you disable the account and access ends in that action.

What happens to our data after the engagement?

It stays in your systems, because that is where it was produced. Lumensoft retains no working copies. The only retained data is encrypted backup held for restoration as disaster-recovery support.

Related services

Where to go next.

Assurance answers what carries the risk. What the work costs is a separate question, answered on Pricing, and how an engagement actually runs is on How We Work.

Book a 30-minute discovery call.

You will speak with a practicing Solution Architect, and anything on this page can be evidenced on that call rather than three weeks into procurement.