Security controlsfor enterprise deployments.
To assess a deployment, compare its data, access, and infrastructure controls with your requirements. Request the documents that support each control before approval.
SOC 2 control review
Review security, availability, and confidentiality controls against SOC 2 requirements. Request the available evidence for the selected deployment.
ISO 27001 framework
Review the information security management system and available partner certificates against the requirements for the selected deployment.
Encryption
Review encryption at rest, TLS protection in transit, server certificates, and backup encryption for the selected infrastructure.
Key lifecycle management
Define key storage, rotation, access, and recovery procedures for the selected deployment.
Audit logging
Review records for model jobs, user actions, and access changes. Define the audit scope and review frequency for the deployment.
Access control
Use organization roles, API keys, and account controls. Review additional identity requirements with the deployment team.
Tenant isolation
Review organization boundaries and resource permissions. Define data and compute isolation for the selected infrastructure.
Data use
Review the permitted use of customer data, retention periods, and deletion procedures before deployment.
Privacy requirements
Review the applicable privacy requirements and request the available vendor documents for the deployment.
Data residency
Define the permitted regions for data storage and processing. Review managed and private cloud options against those requirements.
Infrastructure security
Review network isolation, vulnerability checks, and incident detection for the selected infrastructure.
Deployment flexibility
Compare managed and private cloud deployments against the defined legal and operational requirements.
Review security requirementsagainst the deployment controls.
To assess a deployment, a 30-minute call covers SOC 2, ISO 27001, vendor questionnaires, regional data residency, and the required evidence.