Self-serve assessment

Answer a questionnaire yourself

Each answer is generated from this organization's live control posture - not a vendor-written response. Cross-check any answer against the Trust Center and confirm the evidence integrity in the transparency log.

CAIQ-lite (Cloud Security Alliance)SIG-lite (Shared Assessments)CAIQ v4 (Cloud Security Alliance, full domains)SIG Core (Shared Assessments)

Do you undergo independent third-party audits (e.g. SOC 2, ISO 27001), and how often?

No automated answer available; this question needs a manual response.

Confidence 8%

Can you provide your most recent audit report or certification?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have an internal audit or compliance function?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you follow a secure software development lifecycle (SSDLC)?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you perform application security testing (SAST/DAST) before release?

No automated answer available; this question needs a manual response.

Confidence 8%

Are APIs authenticated, authorized, and rate-limited?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a business continuity and disaster recovery plan, and is it tested?

No automated answer available; this question needs a manual response.

Confidence 8%

What are your recovery time and recovery point objectives (RTO/RPO)?

No automated answer available; this question needs a manual response.

Confidence 8%

Are backups encrypted, and are restores tested regularly?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

Do you have a documented change management process with approvals?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you maintain secure baseline configurations for systems?

No automated answer available; this question needs a manual response.

Confidence 8%

Are production changes peer-reviewed and logged?

No automated answer available; this question needs a manual response.

Confidence 8%

Is data encrypted at rest using industry-standard algorithms?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

Is data encrypted in transit using TLS 1.2 or higher?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

How are encryption keys generated, stored, rotated, and revoked?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

Where is customer data hosted, and are the facilities certified (e.g. SOC 2, ISO 27001)?

No automated answer available; this question needs a manual response.

Confidence 8%

Are physical access controls in place at your data centers?

No automated answer available; this question needs a manual response.

Confidence 8%

How do you classify and handle sensitive and personal data?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a documented data retention and secure disposal policy?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you support data residency or regional data storage requirements?

No automated answer available; this question needs a manual response.

Confidence 8%

How do you honor data subject access, deletion, and portability requests?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a management-approved information security policy?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you maintain a risk register and perform periodic risk assessments?

No automated answer available; this question needs a manual response.

Confidence 8%

Is there a named individual accountable for information security?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you perform background checks on employees where legally permitted?

No automated answer available; this question needs a manual response.

Confidence 8%

Do employees complete security awareness training, and how often?

The workforce completes annual security-awareness training. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in security-awareness-training

Do you have formal onboarding and offboarding procedures?

Access is provisioned on hire and removed on departure. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in onboarding-offboarding

Is access granted on a least-privilege, role-based basis?

No automated answer available; this question needs a manual response.

Confidence 8%

Is multi-factor authentication enforced for administrative and remote access?

Multi-factor authentication is enforced for human access. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in aws-mfa-enforced

Do you perform periodic user access reviews and revoke access promptly on termination?

Access is reviewed every quarter. This control is currently failing and remediation is in progress.

Confidence 70%· grounded in quarterly-access-review

Can customers export their data in a standard, machine-readable format?

No automated answer available; this question needs a manual response.

Confidence 8%

Is your network segmented, and how is traffic between segments controlled?

No automated answer available; this question needs a manual response.

Confidence 8%

Are systems hardened against a documented baseline (e.g. CIS Benchmarks)?

No automated answer available; this question needs a manual response.

Confidence 8%

Are security-relevant audit logs enabled, centralized, and retained?

Audit logging is enabled and retained. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in cloudtrail-audit-logging

Do you monitor for and alert on anomalous or unauthorized activity?

No automated answer available; this question needs a manual response.

Confidence 8%

Are logs protected against tampering?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a documented incident response plan, and is it tested?

A documented incident-response plan is in place. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in incident-response-plan

How and within what timeframe do you notify customers of a security incident?

A documented incident-response plan is in place. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in incident-response-plan

Do you retain forensic evidence to support incident investigation?

A documented incident-response plan is in place. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in incident-response-plan

Do you maintain a current list of subprocessors and notify customers of changes?

No automated answer available; this question needs a manual response.

Confidence 8%

Are third-party vendors assessed for security risk before and during engagement?

No automated answer available; this question needs a manual response.

Confidence 8%

Do your contracts flow down security and privacy obligations to subprocessors?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you perform regular vulnerability scanning and remediate on a defined SLA?

Vulnerability scanning runs continuously. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in inspector-vuln-scanning

Do you conduct penetration testing, and how often?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have anti-malware protection on servers and endpoints?

Workforce devices are managed, encrypted, and screen-locked. This control is currently failing and remediation is in progress.

Confidence 70%· grounded in device-management

Are managed endpoints encrypted, patched, and centrally managed (MDM)?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

Can you remotely lock or wipe a lost or stolen managed device?

Workforce devices are managed, encrypted, and screen-locked. This control is currently failing and remediation is in progress.

Confidence 70%· grounded in device-management