Trust & security
What a diligence review will find.
A sponsor who likes the product routes it into information security, legal, vendor management and operations. This page is written for that review rather than for the meeting before it, which means it states the 3 items not started and the 8 a reviewer would have to ask us for.
Technical boundary
What the platform can and cannot touch. These are architectural rather than procedural, which is why they are stated first — a control that depends on a process being followed is a weaker claim than one the schema cannot express.
Security programme
Where the company is in the work an institutional vendor review expects. Three of these have not started.
Data and privacy
What is held, for how long, and who can reach it.
Company
What a vendor-management review asks before anything technical. These rows are blank on purpose: they are facts only the company can supply, and filling them with something plausible is the fastest way to fail the diligence it is meant to pass.
Send the questionnaire
Security and vendor-management questionnaires are answered against this page, not around it. Where a row above reads not started, the questionnaire will say so too — a vendor that answers differently in a document than on its own site is the one diligence slows down.
Or review the integration architectureInclude the review stage you are at and we will answer at that level rather than sending a brochure.
