# Security questionnaire (short form)

Each answer with a document reference. "Yes" without a document is recorded as a vendor statement.

| # | Question | Answer | Document |
| --- | --- | --- | --- |
| 1 | SOC 2 Type II report available, report period | | |
| 2 | ISO/IEC 27001 certificate, scope and expiry | | |
| 3 | Penetration test in the last 12 months, by whom, findings closed | | |
| 4 | Encryption in transit and at rest, algorithms | | |
| 5 | Single sign-on (SAML/OIDC) and SCIM provisioning | | |
| 6 | Role-based access and audit logs, exportable | | |
| 7 | Data residency options | | |
| 8 | Sub-processors list and change notification | | |
| 9 | Incident response: notification within how many hours | | |
| 10 | Backup and recovery objectives (RPO, RTO), last test | | |
| 11 | Vulnerability management: patch timelines by severity | | |
| 12 | Data deletion at contract end: process and confirmation | | |
