Documentarian
Questionnaires customers have sent you, and any you want filled in from your own evidence, with citations.
DocumentsAskQuestionnairesAnswersControlsContextShareExecutive report
Ostend Payments · third-party security assessment 2026
ReceivedAnswered
Claire Anselm · compliance@ostendpayments.example.com · 8/30/2026 · 38 questions
"Our procurement team needs this back before the 15th. Sections 4 and 7 (encryption and sub-processors) are the ones our risk committee reads."
Answer this questionnaire
Drafting 38 answers from your documents, check results and approved answers…
35 drafted with citations 2 from approved answers 1 gap
36 drafted with citations 2 from approved answers 0 gaps
Download completed xlsxostend-security-assessment-2026.xlsx · answers written into their file
4.1How is customer data encrypted at rest?All customer data is encrypted at rest with AES-256. The production database uses a customer-managed KMS key with annual rotation, and object storage uses the same key.Approved answer · reused 22×Encryption & Data Protection policyApproved
4.2Are storage buckets protected from public access?Yes. 14 of 14 buckets block public access.AC-S3-004 pass · today 09:11PR #219Drafted · high
4.3Is multi-factor authentication enforced on privileged accounts?Yes for all federated and IAM users. The exception is the AWS root account, which has no MFA device yet; it is tracked as open finding AC-IAM-002.AC-IAM-002 failAccess review · Aug 28Drafted · high
7.1List your sub-processors and the data each handles.AWS (hosting, us-east-1), GitHub (source code), Google Workspace (email and documents), each with its data categories and region.Subprocessor & vendor register · approvedDrafted · high
7.3Do you have a formal vendor risk management process?No source found. Not answered. Add the policy, or tell me.Yes. Tier 1 vendors, those that store or process customer data, are reviewed annually and approved by the CTO before any customer data is shared.Vendor / Third-Party Risk Management Policy · approved todayGap Draft a policyDrafted · high
Vendor / Third-Party Risk Management Policy
Generated In review · owner David ThompsonApproved by David Thompson
Maps to SOC 2 CC9.2 · drafted from your documents and connected account
Purpose
Sets how Aster Ridge Labs selects, reviews and monitors the vendors that handle customer data. Subprocessor & vendor register
Vendor tiers
Tier 1 vendors store or process customer data (AWS, GitHub, Google Workspace) and are reviewed annually. Tier 2 vendors never receive customer data. Subprocessor & vendor register
Approval
Not found in your documents: who approves a new Tier 1 vendor before customer data is shared?
The CTO approves new Tier 1 vendors.Answer and I will add it to the draft
The CTO approves each new Tier 1 vendor before any customer data is shared. Answered by David Thompson
Approve policy