Self-serve assessment
Answer a questionnaire yourself
Each answer is generated from this organization's live control posture - not a vendor-written response. Cross-check any answer against the Trust Center and confirm the evidence integrity in the transparency log.
Do you have an information security policy approved by management?
No automated answer available; this question needs a manual response.
Is there a named individual responsible for information security?
No automated answer available; this question needs a manual response.
Do you encrypt sensitive data at rest and in transit?
Data is encrypted at rest using AWS KMS. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
How is access to production systems controlled?
No automated answer available; this question needs a manual response.
Do you have a formal onboarding and offboarding process?
Access is provisioned on hire and removed on departure. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Are third-party vendors assessed for security risk?
No automated answer available; this question needs a manual response.
Do you have a current SOC 2 or ISO 27001 report?
No automated answer available; this question needs a manual response.
How are security patches applied and tracked?
No automated answer available; this question needs a manual response.
Do you have endpoint protection on managed devices?
Workforce devices are managed, encrypted, and screen-locked. This control is currently failing and remediation is in progress.
Do you log and monitor security events?
No automated answer available; this question needs a manual response.
Do you have a documented data retention and disposal policy?
No automated answer available; this question needs a manual response.
Do you conduct penetration testing, and how often?
No automated answer available; this question needs a manual response.
How do you handle and notify customers of a data breach?
No automated answer available; this question needs a manual response.
Do you support single sign-on (SSO) and MFA for customers?
Multi-factor authentication is enforced for human access. This is monitored continuously and currently passing, backed by signed, tamper-evident evidence.
Do you perform periodic user access reviews?
Access is reviewed every quarter. This control is currently failing and remediation is in progress.