Security questionnaire: prefilled answers
Answers to common questions in SIG Lite / CAIQ-style vendor questionnaires. Last updated 2026-09-25. Copy the answer; adjust wording to the form.
Answer key: Yes = in place today. Partial = some of it in place (explained). Planned = not in place; target given. No = not in place and not planned now. N/A = does not apply.
Before sending: re-check every "Planned" item. Do not upgrade an answer to "Yes" until it is true.
A. Company and governance
| # | Question | Answer | Detail |
|---|---|---|---|
| A1 | Do you have a written information security policy? | Partial | Security overview, access control, incident response, business continuity and vulnerability management documents exist (this trust package). A single signed master policy is planned with SOC 2 readiness. |
| A2 | Who is responsible for security? | Yes | The founder, who is the only employee. |
| A3 | How many employees / contractors have access to customer data? | Yes | One (the founder). No contractors. |
| A4 | Are policies reviewed at least annually? | Planned | Review dates set in each document; first annual review due 2027-09. |
| A5 | Do employees sign confidentiality agreements and complete security training? | Planned | For future hires. The founder completes annual security training (to be recorded). |
| A6 | Do you perform background checks? | Planned | For future hires with production access. |
| A7 | Do you have a SOC 2 report? | No | Not obtained. Readiness work under way; see soc2-readiness.md. |
| A8 | ISO 27001 or other certification? | No | — |
| A9 | Do you carry cyber liability insurance? | Planned | Being quoted. |
| A10 | Have you had a security breach in the last 3 years? | No | The product is new; no incidents. |
B. Risk and vendor management
| # | Question | Answer | Detail |
|---|---|---|---|
| B1 | Do you perform a risk assessment at least annually? | Planned | First formal assessment with SOC 2 readiness. |
| B2 | Do you maintain a list of subprocessors? | Yes | subprocessors.md: AWS, Neon, Netlify, Resend, Stripe, Sentry (+ Anthropic, off). |
| B3 | Do you review subprocessors' security (SOC 2 reports, DPAs)? | Planned | Collection of DPAs and SOC 2 reports not yet complete; required before go-live. |
| B4 | Will you notify us before adding a subprocessor? | Yes | For any subprocessor that sees check or client data. |
| B5 | Where is our data stored? | Yes | United States only: AWS us-east-1 or us-east-2, Neon US region. |
C. Data protection and privacy
| # | Question | Answer | Detail |
|---|---|---|---|
| C1 | What customer data do you store? | Yes | Staff names/emails; check details (payer, client, amount, check number, dates, payee, bank); check images; client account numbers (encrypted); only last 4 digits of routing and check account numbers; audit log with IP addresses. No SSNs, card numbers or bank logins. |
| C2 | Is data encrypted at rest? | Yes | S3: SSE-KMS with a customer-managed key. Postgres: Neon storage encryption. Sensitive fields additionally AES-256-GCM in the application, key wrapped by AWS KMS. |
| C3 | Is data encrypted in transit? | Yes | TLS for all connections; S3 rejects TLS below 1.2; Neon requires TLS. |
| C4 | Who manages encryption keys? | Yes | CheckTrail, in AWS KMS (customer-managed key, automatic yearly rotation). Customer-supplied keys (BYOK) are not offered. |
| C5 | Is customer data used to train AI models? | Yes (No use) | CheckTrail does not train models. Textract is used under an AWS AI services opt-out policy (must be applied before go-live — Planned). Anthropic is off unless a zero-data-retention agreement is signed. |
| C6 | Do you minimise sensitive data? | Yes | Only last 4 of routing/check account numbers kept; photo metadata incl. GPS stripped; emails contain no images or account numbers. |
| C7 | How is data segregated between customers? | Yes | Logical separation: every record carries a firm ID and every query is scoped by it; automated tests prove no cross-firm access. Shared database and bucket. |
| C8 | Data retention period? | Yes | Set per firm, default and minimum 6 years; images and exports locked write-once for that period. |
| C9 | Can we get our data back on termination? | Yes | Exam-package exports (PDF, CSV, JSON, images, audit trail, hash manifest) remain available, including when the subscription has lapsed. |
| C10 | Do you delete data on request / on termination? | Partial | Records under retention cannot be deleted (by design, for books-and-records rules). A deletion process after retention ends is Planned. |
| C11 | Do you have a privacy policy? | Planned | Customer-facing privacy notice and DPA template to be drafted with counsel. |
| C12 | Do you process data of EU/UK residents? | N/A | US broker-dealers; US hosting only. |
D. Identity and access management
| # | Question | Answer | Detail |
|---|---|---|---|
| D1 | Is MFA required for users of your application? | Yes | Authenticator-app 2FA required for every password sign-in; or the firm's SSO. |
| D2 | Do you support SSO (SAML / OIDC)? | Partial | Being built; per-firm OIDC and SAML with optional enforcement. Target: before first live firm. |
| D3 | Password policy? | Yes | Minimum 12 characters, common/obvious passwords refused, argon2id hashing. |
| D4 | Account lockout? | Yes | 5 failed attempts → 15-minute lock; per-IP and per-user rate limits. |
| D5 | Session timeout? | Yes | 30 minutes idle, 12 hours absolute; server-side, revocable. |
| D6 | Role-based access control? | Yes | Rep, principal, home office compliance, firm admin; branch scoping; server-side enforcement. |
| D7 | Can customers manage their own users? | Yes | Invite, change roles, deactivate; all audited. |
| D8 | Is MFA required for your staff's production access? | Yes | On every production console (policy). Verification of each account's MFA recorded at first quarterly review — Planned. |
| D9 | Are access reviews performed? | Planned | Quarterly; first at go-live. |
| D10 | Is production access restricted? | Yes | Founder only. App uses least-privilege machine identities (no delete rights). |
| D11 | Can your staff see our data? | Partial | The founder, as sole administrator, technically can. Access only to operate the service or at your request; logged. CloudTrail logging of AWS access: Planned. |
E. Application security
| # | Question | Answer | Detail |
|---|---|---|---|
| E1 | Secure development practices? | Partial | Typed code, schema validation on all inputs, automated tests for authorization and tenant isolation, code review by the founder. CI pipeline Planned. |
| E2 | Do you scan dependencies for vulnerabilities? | Planned | npm audit in CI and Dependabot; not yet configured. |
| E3 | Has an independent penetration test been performed? | No | Planned before the first live firm, then yearly. |
| E4 | Do you use static code analysis (SAST)? | Planned | Linting in place; SAST (e.g. GitHub CodeQL) Planned. |
| E5 | OWASP Top 10 protections? | Partial | Parameterised queries (Prisma), input validation, server-side authorization, HttpOnly/Secure cookies, file-type sniffing. Security headers and nonce-based CSP being built. |
| E6 | File upload protections? | Yes | 15 MB limit, type detected from content, images re-encoded and metadata stripped, only images/PDF/CSV accepted, never served from a public URL. |
| E7 | Is sensitive data kept out of logs? | Yes | No request bodies or check data logged. Sentry scrubber (being built) removes bodies, cookies and 6+ digit runs. |
| E8 | Rate limiting? | Yes | On sign-in and 2FA, stored in Postgres (holds across servers). |
| E9 | Separate environments? | Yes | Development and tests use local storage, mock OCR and fake data; production uses separate credentials. |
| E10 | Change management? | Partial | All changes in version control; production deploys from main. Required CI checks before deploy: Planned. |
F. Infrastructure and operations
| # | Question | Answer | Detail |
|---|---|---|---|
| F1 | Hosting providers? | Yes | Netlify (application), AWS (files, keys, OCR), Neon (database). |
| F2 | Is infrastructure defined as code? | Yes | AWS resources in Terraform. |
| F3 | Firewalls / network controls? | Partial | Fully managed/serverless platforms; S3 public access blocked; bucket policy enforces TLS. No self-managed servers. |
| F4 | Logging and monitoring? | Partial | Application audit log (hash-chained), S3 access logs. Sentry error monitoring being set up. CloudTrail trail and alerting Planned. |
| F5 | Are logs protected from tampering? | Partial | Application audit log is insert-only and hash-chained; S3 access logs in a versioned, private bucket. |
| F6 | Anti-malware on endpoints? | Partial | Founder's laptop runs the operating system's built-in protection. To be verified and recorded at the first quarterly review. |
| F7 | Are endpoints encrypted? | Planned | Full-disk encryption on the founder's laptop must be confirmed (Windows Home editions may only offer "Device encryption", not BitLocker). Verify and record before go-live. |
| F8 | Time synchronisation? | Yes | Managed platforms (AWS, Netlify, Neon) use provider-synchronised clocks; all times stored in UTC. |
G. Business continuity and disaster recovery
| # | Question | Answer | Detail |
|---|---|---|---|
| G1 | Do you back up customer data? | Yes | Neon point-in-time restore; S3 versioning with Object Lock (cannot be deleted). |
| G2 | Are backups tested? | No | Restore procedure written; first test Planned before go-live, then every 6 months. |
| G3 | RPO / RTO? | Partial | Targets: minutes / 8 business hours for the database; zero loss for files. Not yet validated by test. |
| G4 | Multi-region / geographic redundancy? | No | Single US region per provider; providers replicate across facilities within the region. Cross-region copy Planned (not scheduled). |
| G5 | Business continuity plan? | Yes | business-continuity.md. Key-person risk (one founder) acknowledged; backup contact not yet named. |
H. Incident response
| # | Question | Answer | Detail |
|---|---|---|---|
| H1 | Documented incident response plan? | Yes | incident-response-plan.md. Not yet exercised (tabletop Planned). |
| H2 | Breach notification timeline? | Yes | Without undue delay and within 72 hours of confirming an incident affecting your data. |
| H3 | Will you support our Regulation S-P obligations? | Yes | 72-hour notice to the firm and the details needed for your client notifications. Contract terms to be confirmed with counsel. |
| H4 | Do you preserve forensic evidence? | Yes | Procedure in the plan; records are insert-only / locked, which preserves history. |
I. Records (broker-dealer specific)
| # | Question | Answer | Detail |
|---|---|---|---|
| I1 | Are records immutable? | Yes | Edits create versions; record tables insert-only via DB triggers and a restricted role; files locked in S3 Object Lock compliance mode. |
| I2 | Is there an audit trail of all access and changes? | Yes | Every view, edit, sign-off, export and sign-in; hash-chained per firm. |
| I3 | Does the system meet SEC Rule 17a-4(f)? | Partial | Designed for it (WORM storage for images/exports; audit trail for structured records). Legal review pending; see recordkeeping.md open questions. |
| I4 | Will you provide a third-party undertaking (17a-4(f)(3)(iii) / 17a-4(i))? | Planned | Under review with counsel. Not yet offered. |
| I5 | Can records be produced for regulators quickly? | Yes | One-click exam package; time-limited, audited examiner links. |
| I6 | What happens to records if we stop paying? | Yes | Read-only access, exports always available, nothing deleted before retention ends. |