Self-serve assessment

Answer a questionnaire yourself

Each answer is generated from this organization's live control posture - not a vendor-written response. Cross-check any answer against the Trust Center and confirm the evidence integrity in the transparency log.

CAIQ-lite (Cloud Security Alliance)SIG-lite (Shared Assessments)CAIQ v4 (Cloud Security Alliance, full domains)SIG Core (Shared Assessments)

Is data encrypted at rest?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

Is data encrypted in transit using TLS?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

Is multi-factor authentication enforced for administrative access?

Multi-factor authentication is enforced for human access. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in aws-mfa-enforced

Do you enforce a strong password policy?

A strong password policy is enforced. This control is currently failing and remediation is in progress.

Confidence 70%· grounded in aws-strong-password-policy

Are audit logs enabled and retained?

Audit logging is enabled and retained. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in cloudtrail-audit-logging

Do you perform periodic user access reviews?

Access is reviewed every quarter. This control is currently failing and remediation is in progress.

Confidence 70%· grounded in quarterly-access-review

Do you have a documented incident response plan?

A documented incident-response plan is in place. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in incident-response-plan

Do you perform regular vulnerability scanning?

Vulnerability scanning runs continuously. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in inspector-vuln-scanning

Do you maintain an inventory of information assets?

No automated answer available; this question needs a manual response.

Confidence 8%

Are backups performed and tested regularly?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a documented change management process?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you conduct security awareness training for employees?

The workforce completes annual security-awareness training. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in security-awareness-training

Do you maintain a list of subprocessors?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a business continuity and disaster recovery plan?

No automated answer available; this question needs a manual response.

Confidence 8%

Is access granted on a least-privilege basis?

No automated answer available; this question needs a manual response.

Confidence 8%