Security
- Data encryption in transit
- Data encrypted at rest using AES-256 encryption
- Access controls & role-based permissions
- immediate access revocation/ off-boarding controls
- Principle of least privilege
- Secure authentication
- Regular security test / reviews
- Backup & disaster recovery approach
- User enumeration
- Application security protections (SQL Injection & form input restrictions)
- Formal risk management
- Secure SDLC
- Continuous monitoring & alerts
- Annual third-party testing/ pentests
Compliance & Regulations
- GDPR Compliance statement
- Data processing agreements (available on request)
- Planned certifications (ISO27001, SOC2)
- Regional data handling commitments
Privacy & Data Collection
- What data we collect
- Why we collect it
- How long it is retained for
- Who can access it
- Links to privacy policy
- GDPR right to be forgotten + data export controls
AI & Data Usage
- Is coaching data isolated per customer?
- Is data used to train models?
- Human access boundaries
- Safeguards & monitoring
Policies & Documentation
- Information security policy
- Access control policy
- Incident response policy
- Data protection policy
- Acceptable/ fair usage policy
- Background checks for staff
Infrastructure & Hosting
- Cloud providers
- Data storage locations
- High-level architecture
- Availability and resilience basics
- Business continuity/ disaster recovery
Incident Response
- How are incidents detected?
- Response timelines
- Customer notification process
- Post-incident reviews
- Incident response plan/ playbook
Third-Party Sub-processors
- Cloud providers
- AI providers
- Analytical tools (if any)
- What each of these are used for
- Security review of third party sub processors
Contact & Responsible Disclosure
- Security contact email
- How to report vulnerabilities
- Response expectations