Self-serve assessment
Answer a questionnaire yourself
Each answer is generated from this organization's live control posture - not a vendor-written response. Cross-check any answer against the Trust Center and confirm the evidence integrity in the transparency log.
Do you have a management-approved information security policy reviewed at least annually?
No automated answer available; this question needs a manual response.
Is there a named executive accountable for information security and privacy?
No automated answer available; this question needs a manual response.
Do you maintain an asset inventory of systems that store or process sensitive data?
No automated answer available; this question needs a manual response.
How is access to production systems and customer data controlled and reviewed?
No automated answer available; this question needs a manual response.
Is multi-factor authentication enforced for privileged and remote access?
Multi-factor authentication is enforced for human access. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you have formal onboarding and offboarding procedures with timely access revocation?
Access is provisioned on hire and removed on departure. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you perform background checks on personnel where legally permitted?
No automated answer available; this question needs a manual response.
Do employees complete security awareness training at hire and annually?
The workforce completes annual security-awareness training. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Is sensitive data encrypted at rest and in transit with industry-standard algorithms?
Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
How are cryptographic keys managed, rotated, and protected?
No automated answer available; this question needs a manual response.
Do you maintain a documented change management process with approvals and testing?
No automated answer available; this question needs a manual response.
Do you enforce secure baseline configurations and system hardening?
No automated answer available; this question needs a manual response.
Do you perform vulnerability scanning and remediate findings on a defined SLA?
Vulnerability scanning runs continuously. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you conduct independent penetration testing at least annually?
No automated answer available; this question needs a manual response.
Do you have endpoint protection, encryption, and patch management on managed devices?
Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Are security events logged, centralized, retained, and monitored for anomalies?
No automated answer available; this question needs a manual response.
Do you have a documented, tested incident response plan?
A documented incident-response plan is in place. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
What is your customer breach-notification process and timeline?
No automated answer available; this question needs a manual response.
Do you have a tested business continuity and disaster recovery plan with defined RTO/RPO?
No automated answer available; this question needs a manual response.
Are backups encrypted and periodically restore-tested?
Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you maintain a current SOC 2 Type II or ISO 27001 certification?
No automated answer available; this question needs a manual response.
Do you assess third-party vendors and subprocessors for security risk?
No automated answer available; this question needs a manual response.
Do you maintain and publish a current subprocessor list?
No automated answer available; this question needs a manual response.
Do you have a documented data classification, retention, and secure disposal policy?
No automated answer available; this question needs a manual response.
How do you support data subject access, deletion, and portability requests?
No automated answer available; this question needs a manual response.
Do you support data residency requirements, and where is data hosted?
No automated answer available; this question needs a manual response.
Are your hosting facilities independently certified (SOC 2 / ISO 27001)?
No automated answer available; this question needs a manual response.
Is your network segmented with controlled traffic between zones?
No automated answer available; this question needs a manual response.
Do you follow a secure software development lifecycle with code review and security testing?
Source-control branches require reviewed pull requests. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you offer SSO and MFA options to customers?
Multi-factor authentication is enforced for human access. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.