Boardroom Answers · People & Operations · Operational Excellence
Standard vendor diligence: SOC 2 report, DPA, security questionnaire, subprocessor list, insurance. What can you hand me today, and what will bounce?
The question a Chief Procurement Officer (CPO-P) asks.
The short answer
DPA, SCCs, subprocessor list and security policy are published and ready today. SOC 2 is not — that is a contracted roadmap milestone, with database-enforced tenant isolation and CI-verified controls as the compensating story.
The full executive answer
Let me give you the honest split. Hand you today: a Data Processing Agreement — published at a permanent URL on our legal pages — alongside Standard Contractual Clauses for international transfers, a public subprocessor list, a security policy page, and a security.txt with a committed one-business-day acknowledgement for security reports. Our trust page documents the AI-governance posture. Security questionnaires: I complete them personally, and because I built the system, the answers are precise and fast — founding customers have found that a feature rather than a gap.
What bounces: SOC 2. We do not hold a SOC 2 report today, and I will not dress that up. What I can offer instead is unusual technical transparency as the compensating control: tenant isolation enforced in the database itself through row-level security — with an automated CI test that fails the build if any tenant table lacks an isolation policy — append-only audit logs, PII redaction before any text reaches an AI model, secrets never in code, and a quality gate of several hundred test suites on every change. Where a SOC 2 attests processes, I can show you the enforcing code. SOC 2 Type I then Type II is a funded roadmap commitment that lands with early revenue, and I will contract the milestone.
Insurance: professional indemnity and cyber cover appropriate to an early-stage vendor is part of our enterprise contracting posture — the specifics are order-form territory and I would rather confirm exact coverage in writing than approximate it in a demo. If your process has a hard SOC 2 gate with no exceptions path, tell me now and we will scope a timeline rather than waste your cycle — some procurement teams run an early-vendor exception with compensating controls, and we are built to pass exactly that review.
Grounded in: ITIL 4 supplier management viewed from the customer side — plus the compensating-controls pattern from standard third-party-risk frameworks for pre-attestation vendors.
The natural next questions
Related governed answers
- You are a one-person company. If you get hit by a bus, sign with a competitor, or simply burn out, my organisation has built board processes on a dead product. Why would I ever accept that risk?
- Walk me through the commercial model — tiers, seats, what triggers overage, and where the hidden costs are, because there are always hidden costs with AI products.?
- Your product is a wrapper on other people's infrastructure — Vercel, Supabase, Anthropic, OpenAI, Clerk. How do you manage YOUR vendors, and what happens to me when one of them fails or changes terms?
Want this answered live, on your data?