Home › Vendor Due Diligence › Vendor Security Questionnaire (Public Response)
Vendor Security Questionnaire
Format: Shared Assessments SIG Lite (130 questions across 18 domains)
Revision: May 3, 2026
Scope: Public revision suitable for sharing without non-disclosure agreement. The internal full SIG (~900 questions) is released to qualified prospects under NDA.
Owner: Office of the Chief Information Security Officer (cross-signed by General Counsel)
Answers below are the Company's affirmative attestations as of the revision date. Where evidence is described as "available on request," the supporting document is released under non-disclosure agreement; the inventory is at /vendor-due-diligence .
Domain A - Risk Assessment and Treatment
Q# Question Answer Detail
A.1 Does the vendor maintain an Information Security Management System (ISMS)? Yes ISO 27001-aligned. Summary at Information Security Policy .
A.2 Is the ISMS reviewed at least annually? Yes Annual ISMS management review by the CISO; record retained.
A.3 Is a HIPAA Security Rule risk analysis performed? Yes Annual; executive summary at HIPAA Risk Assessment Summary .
Domain B - Security Policy
Q# Question Answer Detail
B.1 Are security policies documented and approved by management? Yes Twenty-four policy documents; reviewed at least annually.
B.2 Are policies communicated to all personnel? Yes Personnel acknowledge on hire and on each material update.
Domain C - Organizational Security
Q# Question Answer Detail
C.1 Is there a designated CISO with executive authority? Yes Reports to the CEO; presents to the Board quarterly.
C.2 Is segregation of duties enforced for sensitive operations? Yes PR review (two-eye); production change requires Engineering + Operations sign-off.
Domain D - Asset and Information Management
Q# Question Answer Detail
D.1 Does the vendor maintain an asset inventory? Yes CMDB; per-service ownership matrix.
D.2 Is data classified by sensitivity? Yes Four-tier classification; PHI is "Restricted."
D.3 Is a PHI data flow diagram maintained? Yes PHI Data Flow Diagram .
Domain E - Human Resources Security
Q# Question Answer Detail
E.1 Are background checks performed? Yes Commensurate with role sensitivity at hire.
E.2 Is security and HIPAA training mandatory? Yes Within 7 days of hire; annually thereafter; role-based modules.
E.3 Are confidentiality agreements signed? Yes Standard at hire; updated on material role change.
Domain F - Physical and Environmental
Q# Question Answer Detail
F.1 Are data centers physically secured? Inherited AWS data centers; SOC 2 + ISO 27001 + FedRAMP High audited.
F.2 Is there an office security policy? N/A Remote-first; no physical office in scope.
Domain G - Operations and Communications
Q# Question Answer Detail
G.1 Is change control formal and documented? Yes GitHub PR + CI gate + two-eye review; no manual production changes.
G.2 Are infrastructure secrets managed via a vault? Yes AWS Secrets Manager + KMS; CI/CD secrets injected at deploy.
G.3 Are container images signed? Yes Signed on build; signature verified on deploy.
Domain H - Access Control
Q# Question Answer Detail
H.1 Is multi-factor authentication enforced for privileged access? Yes WebAuthn (FIDO2 hardware key) primary; TOTP backup. No password-only access.
H.2 Is privileged access just-in-time? Yes Time-boxed elevation, full audit log.
H.3 Are accounts reviewed periodically? Yes Quarterly access review; automated stale-account expiry.
Domain I - Application Security
Q# Question Answer Detail
I.1 Is SAST performed in CI? Yes Snyk on every PR.
I.2 Are software dependencies scanned? Yes Snyk + Dependabot; SBOM per release.
I.3 Is a secure SDLC documented? Yes Internal SDLC document released under NDA.
Domain J - Cybersecurity Incident Management
Q# Question Answer Detail
J.1 Is there a documented Incident Response Plan? Yes Incident Response Plan Summary .
J.2 What is the customer notification SLA for PHI breach? 60 min Statutory floor is 60 days under 45 C.F.R. § 164.410.
J.3 Are tabletop exercises performed? Yes Quarterly.
Domain K - Operational Resilience
Q# Question Answer Detail
K.1 What is the RTO? 4 hours Multi-region failover; BCP Summary .
K.2 What is the RPO? 1 hour Cross-region replication.
K.3 Are restore-from-backup tests performed? Yes Semi-annual.
Domain L - Compliance
Q# Question Answer Detail
L.1 HIPAA Active BAA-ready; BAA Template .
L.2 SOC 2 Type II In flight Observation period engaged; report Q3 2027.
L.3 HITRUST CSF i1 In flight Engagement letter signed; cert target Q4 2026.
L.4 HITRUST CSF r2 Planned Start Q1 2027; cert target Q3 2027.
L.5 FedRAMP Planned Federal-track sponsorship pending.
L.6 NIST CSF 2.0 Mapped Self-attested; mapping available on request.
L.7 External penetration test Scheduled Annual; executive summary released to customers within 60 days.
Domain M - End-User Device Security
Q# Question Answer Detail
M.1 Are operator endpoints managed? Yes MDM-enrolled; full-disk encryption mandatory.
M.2 Is endpoint detection and response deployed? Yes EDR on all production-access endpoints.
Domain N - Network Security
Q# Question Answer Detail
N.1 Is the production environment network-isolated? Yes VPC + private subnets; no internet egress for inference.
N.2 Is a WAF in place? Yes AWS WAF on public surfaces.
N.3 Is mutual TLS used internally? Yes Service-to-service mTLS.
Domain O - Privacy
Q# Question Answer Detail
O.1 Is PHI tokenized at the boundary? Yes FF3-1 / FPE-AES; analytical pipeline operates on tokenized data only.
O.2 Are GDPR or CCPA in scope? No Not in production scope today.
Domain P - Threat and Vulnerability Management
Q# Question Answer Detail
P.1 Are threat intel feeds consumed? Yes AWS GuardDuty + custom anomaly detectors.
P.2 Patching SLA? Tiered Critical 7 days; High 30 days; Medium 90 days; Low quarterly.
Domain Q - Server Security
Q# Question Answer Detail
Q.1 Are container images hardened? Yes Distroless base; CIS benchmarks applied.
Q.2 Vulnerability scanning of images? Yes AWS Inspector weekly.
Domain R - Cloud Hosting
Q# Question Answer Detail
R.1 Cloud providers in production? AWS Sole production cloud; BAA executed.
R.2 Inheritance of FedRAMP audits available? Yes For GovCloud workloads. Available for federal-track engagements.