Self-serve assessment

Answer a questionnaire yourself

Each answer is generated from this organization's live control posture - not a vendor-written response. Cross-check any answer against the Trust Center and confirm the evidence integrity in the transparency log.

CAIQ-lite (Cloud Security Alliance)SIG-lite (Shared Assessments)CAIQ v4 (Cloud Security Alliance, full domains)SIG Core (Shared Assessments)

Do you have an information security policy approved by management?

No automated answer available; this question needs a manual response.

Confidence 8%

Is there a named individual responsible for information security?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you encrypt sensitive data at rest and in transit?

Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in encryption-at-rest

How is access to production systems controlled?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a formal onboarding and offboarding process?

Access is provisioned on hire and removed on departure. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in onboarding-offboarding

Are third-party vendors assessed for security risk?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a current SOC 2 or ISO 27001 report?

No automated answer available; this question needs a manual response.

Confidence 8%

How are security patches applied and tracked?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have endpoint protection on managed devices?

Workforce devices are managed, encrypted, and screen-locked. This control is currently failing and remediation is in progress.

Confidence 70%· grounded in device-management

Do you log and monitor security events?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you have a documented data retention and disposal policy?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you conduct penetration testing, and how often?

No automated answer available; this question needs a manual response.

Confidence 8%

How do you handle and notify customers of a data breach?

No automated answer available; this question needs a manual response.

Confidence 8%

Do you support single sign-on (SSO) and MFA for customers?

Multi-factor authentication is enforced for human access. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.

Confidence 88%· grounded in aws-mfa-enforced

Do you perform periodic user access reviews?

Access is reviewed every quarter. This control is currently failing and remediation is in progress.

Confidence 70%· grounded in quarterly-access-review