| Access control | SSO with enforced MFA, least-privilege roles, quarterly access review, offboarding within one business day | Access control policy | A.5.15, A.5.16, A.5.18, A.8.2, A.8.5 |
|---|
| Encryption | TLS 1.3 in transit, AES-256 at rest, customer-managed keys where the platform supports it | Architecture note | A.8.24 |
|---|
| Secure development | Peer review on every merge, SAST and dependency scanning in CI, ASVS L2 checklist at release | SDLC policy, sample pipeline run | A.8.25, A.8.26, A.8.28, A.8.29, A.8.31 |
|---|
| Penetration testing | Independent test before each major release and annually thereafter | Executive summary under NDA | A.8.8, A.8.29 |
|---|
| Supply chain | Pinned dependencies, signed builds, SBOM per release, CVE triage within a stated window | SBOM, provenance attestation | A.5.19, A.5.20, A.5.21, A.8.30 |
|---|
| Incident response | Named on-call, severity ladder, customer notification commitment in writing | IR plan, notification SLA | A.5.24, A.5.25, A.5.26, A.6.8 |
|---|
| Business continuity | Documented RTO and RPO per system, restore tested rather than assumed | BCP, last restore test date | A.5.29, A.5.30, A.8.13, A.8.14 |
|---|
| Data protection | Processing register, retention schedule, DSAR workflow, residency options | DPA, sub-processor list | A.5.33, A.5.34, A.8.10, A.8.11 |
|---|
| AI governance | Model inventory, human review on consequential decisions, no client data into third-party training | AI use policy | |
|---|
| People | Background checks where law allows, NDAs, annual security training with completion tracked | Training records summary | A.6.1, A.6.2, A.6.3, A.6.6 |
|---|