Procurement
How a review runs with us: what you receive, who you talk to, and what happens next. Technical answers live in the Security Review FAQ.
Security and technical questions are answered in one place
This page covers how a review runs with us. Every technical answer lives in the documents below, so procurement and security teams are quoting the same wording.
- Security Review FAQ
SSO and SCIM, MFA, tenant isolation, encryption, SOC 2 position, hosting, backups, exports, and the capabilities we do not have.
- Data handling
Storage, encryption, isolation, audit integrity, retention, and deletion.
- Service levels
Availability expectations and support commitments by plan.
- Incident response
Detection, containment, severity classification, and disclosure.
How the review process works
What do we receive when a review starts?▾
How long does security review take?▾
Can we sign a DPA?▾
Who do we talk to, and what happens next?▾
What can teams usually stand up during early evaluation?▾
What teams usually stand up during early evaluation
Initial setup
Enable framework + import existing evidence
Framework mapping
Map controls to evidence + create core policies
Ownership design
Assign owners + set up automation triggers
Posture review
Generate compliance posture report
Buyer review
Review export-ready evidence packages for stakeholders
