Self-serve assessment
Answer a questionnaire yourself
Each answer is generated from this organization's live control posture - not a vendor-written response. Cross-check any answer against the Trust Center and confirm the evidence integrity in the transparency log.
Is data encrypted at rest?
Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Is data encrypted in transit using TLS?
Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Is multi-factor authentication enforced for administrative access?
Multi-factor authentication is enforced for human access. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you enforce a strong password policy?
A strong password policy is enforced. This control is currently failing and remediation is in progress.
Are audit logs enabled and retained?
Audit logging is enabled and retained. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you perform periodic user access reviews?
Access is reviewed every quarter. This control is currently failing and remediation is in progress.
Do you have a documented incident response plan?
A documented incident-response plan is in place. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you perform regular vulnerability scanning?
Vulnerability scanning runs continuously. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you maintain an inventory of information assets?
No automated answer available; this question needs a manual response.
Are backups performed and tested regularly?
No automated answer available; this question needs a manual response.
Do you have a documented change management process?
No automated answer available; this question needs a manual response.
Do you conduct security awareness training for employees?
The workforce completes annual security-awareness training. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you maintain a list of subprocessors?
No automated answer available; this question needs a manual response.
Do you have a business continuity and disaster recovery plan?
No automated answer available; this question needs a manual response.
Is access granted on a least-privilege basis?
No automated answer available; this question needs a manual response.