Procurement pack
Vendor risk review answers (internal / illustrative).
How we're different
- Audit-first exports with evidence links.
- Explicit approvals and policy gates.
- Data minimization posture.
Trust rule: AI drafts; humans decide for sensitive outcomes.
What IT and procurement get
Security questionnaire
Short-form answers for common vendor risk forms.
DPA placeholder
Template language to speed legal review (illustrative).
Incident response overview
What we do, who to contact, and how we communicate.
Short-form answers
Do you train models on our data?
No, not by default. Model usage is provider-agnostic and bounded to drafting and extraction tasks under strict schemas.
What do you store?
Workflow state, evidence references, audit events, and exports needed for exam readiness. Data minimization is a design goal.
How do approvals work?
Policy gates require explicit human approval for sensitive actions (external comms and final decisions).
How do you handle incidents?
We document scope, mitigate, and provide post-incident reporting (illustrative process for internal planning).
Where to go next
- Trust center for the overview and posture pages.
- Security for controls.
- Privacy for data minimization and handling.
- Docs for API and audit trail references.