Security

Security controlsfor enterprise deployments.

To assess a deployment, compare its data, access, and infrastructure controls with your requirements. Request the documents that support each control before approval.

/ 01

SOC 2 control review

Review security, availability, and confidentiality controls against SOC 2 requirements. Request the available evidence for the selected deployment.

/ 02

ISO 27001 framework

Review the information security management system and available partner certificates against the requirements for the selected deployment.

/ 03

Encryption

Review encryption at rest, TLS protection in transit, server certificates, and backup encryption for the selected infrastructure.

/ 04

Key lifecycle management

Define key storage, rotation, access, and recovery procedures for the selected deployment.

/ 05

Audit logging

Review records for model jobs, user actions, and access changes. Define the audit scope and review frequency for the deployment.

/ 06

Access control

Use organization roles, API keys, and account controls. Review additional identity requirements with the deployment team.

/ 07

Tenant isolation

Review organization boundaries and resource permissions. Define data and compute isolation for the selected infrastructure.

/ 08

Data use

Review the permitted use of customer data, retention periods, and deletion procedures before deployment.

/ 09

Privacy requirements

Review the applicable privacy requirements and request the available vendor documents for the deployment.

/ 10

Data residency

Define the permitted regions for data storage and processing. Review managed and private cloud options against those requirements.

/ 11

Infrastructure security

Review network isolation, vulnerability checks, and incident detection for the selected infrastructure.

/ 12

Deployment flexibility

Compare managed and private cloud deployments against the defined legal and operational requirements.

Review security requirementsagainst the deployment controls.

To assess a deployment, a 30-minute call covers SOC 2, ISO 27001, vendor questionnaires, regional data residency, and the required evidence.