01
Do you encrypt data at rest and in transit? Specify algorithms and key lengths.
—
Not started
02
Provide your most recent SOC 2 Type II report.
draft
Needs SME
03
List every sub-processor, their location, and what data they touch.
—
Not started
04
Describe your access control model and least-privilege enforcement.
draft
In progress
05
Confirm in writing that you have never, under any circumstances, used a fax machine.
—
Overdue
06
How often do you run third-party penetration tests? Attach the last two.
—
Not started
07
Do you enforce MFA for all employees and contractors?
draft
In progress
08
What is the exact firmware version of the router in your CEO's home office?
—
Overdue
09
Describe your incident response plan and mean time to containment.
—
Not started
10
What is your data retention and secure destruction policy?
draft
Needs SME
11
Please re-answer questions 1 through 40, but in the third person.
—
Overdue
12
Do you support SSO via SAML 2.0 and SCIM provisioning?
—
Not started
13
Provide evidence of annual employee security awareness training.
draft
In progress
14
List each employee's astrological sign for personnel risk scoring.
—
Overdue
15
Describe your vulnerability management program and patch cadence.
—
Not started
16
What is your measured uptime over the trailing 12 months?
draft
Needs SME
17
How many fire extinguishers sit within 3 meters of a server? Round to 0.5.
—
Overdue
18
Where is customer data physically stored? Name the region and provider.
—
Not started
19
Describe your business continuity and disaster recovery plan.
draft
In progress
20
Does your change management process require peer review before deploy?
—
Not started
01
Do you encrypt data at rest and in transit? Specify algorithms and key lengths.
—
Not started
02
Provide your most recent SOC 2 Type II report.
draft
Needs SME
03
List every sub-processor, their location, and what data they touch.
—
Not started
04
Describe your access control model and least-privilege enforcement.
draft
In progress
05
Confirm in writing that you have never, under any circumstances, used a fax machine.
—
Overdue
06
How often do you run third-party penetration tests? Attach the last two.
—
Not started
07
Do you enforce MFA for all employees and contractors?
draft
In progress
08
What is the exact firmware version of the router in your CEO's home office?
—
Overdue
09
Describe your incident response plan and mean time to containment.
—
Not started
10
What is your data retention and secure destruction policy?
draft
Needs SME
11
Please re-answer questions 1 through 40, but in the third person.
—
Overdue
12
Do you support SSO via SAML 2.0 and SCIM provisioning?
—
Not started
13
Provide evidence of annual employee security awareness training.
draft
In progress
14
List each employee's astrological sign for personnel risk scoring.
—
Overdue
15
Describe your vulnerability management program and patch cadence.
—
Not started
16
What is your measured uptime over the trailing 12 months?
draft
Needs SME
17
How many fire extinguishers sit within 3 meters of a server? Round to 0.5.
—
Overdue
18
Where is customer data physically stored? Name the region and provider.
—
Not started
19
Describe your business continuity and disaster recovery plan.
draft
In progress
20
Does your change management process require peer review before deploy?
—
Not started