← All demos
Aster Ridge Labs · 847219356041DT

Documentarian

Questionnaires customers have sent you, and any you want filled in from your own evidence, with citations.
DocumentsAskQuestionnairesAnswersControlsContextShareExecutive report

Ostend Payments · third-party security assessment 2026

Received
Claire Anselm · compliance@ostendpayments.example.com · 8/30/2026 · 38 questions
"Our procurement team needs this back before the 15th. Sections 4 and 7 (encryption and sub-processors) are the ones our risk committee reads."
Answer this questionnaire
Drafting 38 answers from your documents, check results and approved answers… Download completed xlsx

Vendor / Third-Party Risk Management Policy

Generated In review · owner David Thompson
Maps to SOC 2 CC9.2 · drafted from your documents and connected account
Purpose

Sets how Aster Ridge Labs selects, reviews and monitors the vendors that handle customer data. Subprocessor & vendor register

Vendor tiers

Tier 1 vendors store or process customer data (AWS, GitHub, Google Workspace) and are reviewed annually. Tier 2 vendors never receive customer data. Subprocessor & vendor register

Approval
Not found in your documents: who approves a new Tier 1 vendor before customer data is shared?
The CTO approves new Tier 1 vendors.Answer and I will add it to the draft

The CTO approves each new Tier 1 vendor before any customer data is shared. Answered by David Thompson

Approve policy
Tudovu

Documentarian.

Security questionnaires answered from your own evidence.

0:00 / 0:00