Skip to main content

Boardroom Answers · People & Operations · Operational Excellence

Standard vendor diligence: SOC 2 report, DPA, security questionnaire, subprocessor list, insurance. What can you hand me today, and what will bounce?

The question a Chief Procurement Officer (CPO-P) asks.

The short answer

DPA, SCCs, subprocessor list and security policy are published and ready today. SOC 2 is not — that is a contracted roadmap milestone, with database-enforced tenant isolation and CI-verified controls as the compensating story.

The full executive answer

Let me give you the honest split. Hand you today: a Data Processing Agreement — published at a permanent URL on our legal pages — alongside Standard Contractual Clauses for international transfers, a public subprocessor list, a security policy page, and a security.txt with a committed one-business-day acknowledgement for security reports. Our trust page documents the AI-governance posture. Security questionnaires: I complete them personally, and because I built the system, the answers are precise and fast — founding customers have found that a feature rather than a gap.

What bounces: SOC 2. We do not hold a SOC 2 report today, and I will not dress that up. What I can offer instead is unusual technical transparency as the compensating control: tenant isolation enforced in the database itself through row-level security — with an automated CI test that fails the build if any tenant table lacks an isolation policy — append-only audit logs, PII redaction before any text reaches an AI model, secrets never in code, and a quality gate of several hundred test suites on every change. Where a SOC 2 attests processes, I can show you the enforcing code. SOC 2 Type I then Type II is a funded roadmap commitment that lands with early revenue, and I will contract the milestone.

Insurance: professional indemnity and cyber cover appropriate to an early-stage vendor is part of our enterprise contracting posture — the specifics are order-form territory and I would rather confirm exact coverage in writing than approximate it in a demo. If your process has a hard SOC 2 gate with no exceptions path, tell me now and we will scope a timeline rather than waste your cycle — some procurement teams run an early-vendor exception with compensating controls, and we are built to pass exactly that review.

Grounded in: ITIL 4 supplier management viewed from the customer side — plus the compensating-controls pattern from standard third-party-risk frameworks for pre-attestation vendors.

Want this answered live, on your data?