← Security

Security questionnaire: prefilled answers

Answers to common questions in SIG Lite / CAIQ-style vendor questionnaires. Last updated 2026-09-25. Copy the answer; adjust wording to the form.

Answer key: Yes = in place today. Partial = some of it in place (explained). Planned = not in place; target given. No = not in place and not planned now. N/A = does not apply.

Before sending: re-check every "Planned" item. Do not upgrade an answer to "Yes" until it is true.


A. Company and governance

# Question Answer Detail
A1 Do you have a written information security policy? Partial Security overview, access control, incident response, business continuity and vulnerability management documents exist (this trust package). A single signed master policy is planned with SOC 2 readiness.
A2 Who is responsible for security? Yes The founder, who is the only employee.
A3 How many employees / contractors have access to customer data? Yes One (the founder). No contractors.
A4 Are policies reviewed at least annually? Planned Review dates set in each document; first annual review due 2027-09.
A5 Do employees sign confidentiality agreements and complete security training? Planned For future hires. The founder completes annual security training (to be recorded).
A6 Do you perform background checks? Planned For future hires with production access.
A7 Do you have a SOC 2 report? No Not obtained. Readiness work under way; see soc2-readiness.md.
A8 ISO 27001 or other certification? No —
A9 Do you carry cyber liability insurance? Planned Being quoted.
A10 Have you had a security breach in the last 3 years? No The product is new; no incidents.

B. Risk and vendor management

# Question Answer Detail
B1 Do you perform a risk assessment at least annually? Planned First formal assessment with SOC 2 readiness.
B2 Do you maintain a list of subprocessors? Yes subprocessors.md: AWS, Neon, Netlify, Resend, Stripe, Sentry (+ Anthropic, off).
B3 Do you review subprocessors' security (SOC 2 reports, DPAs)? Planned Collection of DPAs and SOC 2 reports not yet complete; required before go-live.
B4 Will you notify us before adding a subprocessor? Yes For any subprocessor that sees check or client data.
B5 Where is our data stored? Yes United States only: AWS us-east-1 or us-east-2, Neon US region.

C. Data protection and privacy

# Question Answer Detail
C1 What customer data do you store? Yes Staff names/emails; check details (payer, client, amount, check number, dates, payee, bank); check images; client account numbers (encrypted); only last 4 digits of routing and check account numbers; audit log with IP addresses. No SSNs, card numbers or bank logins.
C2 Is data encrypted at rest? Yes S3: SSE-KMS with a customer-managed key. Postgres: Neon storage encryption. Sensitive fields additionally AES-256-GCM in the application, key wrapped by AWS KMS.
C3 Is data encrypted in transit? Yes TLS for all connections; S3 rejects TLS below 1.2; Neon requires TLS.
C4 Who manages encryption keys? Yes CheckTrail, in AWS KMS (customer-managed key, automatic yearly rotation). Customer-supplied keys (BYOK) are not offered.
C5 Is customer data used to train AI models? Yes (No use) CheckTrail does not train models. Textract is used under an AWS AI services opt-out policy (must be applied before go-live — Planned). Anthropic is off unless a zero-data-retention agreement is signed.
C6 Do you minimise sensitive data? Yes Only last 4 of routing/check account numbers kept; photo metadata incl. GPS stripped; emails contain no images or account numbers.
C7 How is data segregated between customers? Yes Logical separation: every record carries a firm ID and every query is scoped by it; automated tests prove no cross-firm access. Shared database and bucket.
C8 Data retention period? Yes Set per firm, default and minimum 6 years; images and exports locked write-once for that period.
C9 Can we get our data back on termination? Yes Exam-package exports (PDF, CSV, JSON, images, audit trail, hash manifest) remain available, including when the subscription has lapsed.
C10 Do you delete data on request / on termination? Partial Records under retention cannot be deleted (by design, for books-and-records rules). A deletion process after retention ends is Planned.
C11 Do you have a privacy policy? Planned Customer-facing privacy notice and DPA template to be drafted with counsel.
C12 Do you process data of EU/UK residents? N/A US broker-dealers; US hosting only.

D. Identity and access management

# Question Answer Detail
D1 Is MFA required for users of your application? Yes Authenticator-app 2FA required for every password sign-in; or the firm's SSO.
D2 Do you support SSO (SAML / OIDC)? Partial Being built; per-firm OIDC and SAML with optional enforcement. Target: before first live firm.
D3 Password policy? Yes Minimum 12 characters, common/obvious passwords refused, argon2id hashing.
D4 Account lockout? Yes 5 failed attempts → 15-minute lock; per-IP and per-user rate limits.
D5 Session timeout? Yes 30 minutes idle, 12 hours absolute; server-side, revocable.
D6 Role-based access control? Yes Rep, principal, home office compliance, firm admin; branch scoping; server-side enforcement.
D7 Can customers manage their own users? Yes Invite, change roles, deactivate; all audited.
D8 Is MFA required for your staff's production access? Yes On every production console (policy). Verification of each account's MFA recorded at first quarterly review — Planned.
D9 Are access reviews performed? Planned Quarterly; first at go-live.
D10 Is production access restricted? Yes Founder only. App uses least-privilege machine identities (no delete rights).
D11 Can your staff see our data? Partial The founder, as sole administrator, technically can. Access only to operate the service or at your request; logged. CloudTrail logging of AWS access: Planned.

E. Application security

# Question Answer Detail
E1 Secure development practices? Partial Typed code, schema validation on all inputs, automated tests for authorization and tenant isolation, code review by the founder. CI pipeline Planned.
E2 Do you scan dependencies for vulnerabilities? Planned npm audit in CI and Dependabot; not yet configured.
E3 Has an independent penetration test been performed? No Planned before the first live firm, then yearly.
E4 Do you use static code analysis (SAST)? Planned Linting in place; SAST (e.g. GitHub CodeQL) Planned.
E5 OWASP Top 10 protections? Partial Parameterised queries (Prisma), input validation, server-side authorization, HttpOnly/Secure cookies, file-type sniffing. Security headers and nonce-based CSP being built.
E6 File upload protections? Yes 15 MB limit, type detected from content, images re-encoded and metadata stripped, only images/PDF/CSV accepted, never served from a public URL.
E7 Is sensitive data kept out of logs? Yes No request bodies or check data logged. Sentry scrubber (being built) removes bodies, cookies and 6+ digit runs.
E8 Rate limiting? Yes On sign-in and 2FA, stored in Postgres (holds across servers).
E9 Separate environments? Yes Development and tests use local storage, mock OCR and fake data; production uses separate credentials.
E10 Change management? Partial All changes in version control; production deploys from main. Required CI checks before deploy: Planned.

F. Infrastructure and operations

# Question Answer Detail
F1 Hosting providers? Yes Netlify (application), AWS (files, keys, OCR), Neon (database).
F2 Is infrastructure defined as code? Yes AWS resources in Terraform.
F3 Firewalls / network controls? Partial Fully managed/serverless platforms; S3 public access blocked; bucket policy enforces TLS. No self-managed servers.
F4 Logging and monitoring? Partial Application audit log (hash-chained), S3 access logs. Sentry error monitoring being set up. CloudTrail trail and alerting Planned.
F5 Are logs protected from tampering? Partial Application audit log is insert-only and hash-chained; S3 access logs in a versioned, private bucket.
F6 Anti-malware on endpoints? Partial Founder's laptop runs the operating system's built-in protection. To be verified and recorded at the first quarterly review.
F7 Are endpoints encrypted? Planned Full-disk encryption on the founder's laptop must be confirmed (Windows Home editions may only offer "Device encryption", not BitLocker). Verify and record before go-live.
F8 Time synchronisation? Yes Managed platforms (AWS, Netlify, Neon) use provider-synchronised clocks; all times stored in UTC.

G. Business continuity and disaster recovery

# Question Answer Detail
G1 Do you back up customer data? Yes Neon point-in-time restore; S3 versioning with Object Lock (cannot be deleted).
G2 Are backups tested? No Restore procedure written; first test Planned before go-live, then every 6 months.
G3 RPO / RTO? Partial Targets: minutes / 8 business hours for the database; zero loss for files. Not yet validated by test.
G4 Multi-region / geographic redundancy? No Single US region per provider; providers replicate across facilities within the region. Cross-region copy Planned (not scheduled).
G5 Business continuity plan? Yes business-continuity.md. Key-person risk (one founder) acknowledged; backup contact not yet named.

H. Incident response

# Question Answer Detail
H1 Documented incident response plan? Yes incident-response-plan.md. Not yet exercised (tabletop Planned).
H2 Breach notification timeline? Yes Without undue delay and within 72 hours of confirming an incident affecting your data.
H3 Will you support our Regulation S-P obligations? Yes 72-hour notice to the firm and the details needed for your client notifications. Contract terms to be confirmed with counsel.
H4 Do you preserve forensic evidence? Yes Procedure in the plan; records are insert-only / locked, which preserves history.

I. Records (broker-dealer specific)

# Question Answer Detail
I1 Are records immutable? Yes Edits create versions; record tables insert-only via DB triggers and a restricted role; files locked in S3 Object Lock compliance mode.
I2 Is there an audit trail of all access and changes? Yes Every view, edit, sign-off, export and sign-in; hash-chained per firm.
I3 Does the system meet SEC Rule 17a-4(f)? Partial Designed for it (WORM storage for images/exports; audit trail for structured records). Legal review pending; see recordkeeping.md open questions.
I4 Will you provide a third-party undertaking (17a-4(f)(3)(iii) / 17a-4(i))? Planned Under review with counsel. Not yet offered.
I5 Can records be produced for regulators quickly? Yes One-click exam package; time-limited, audited examiner links.
I6 What happens to records if we stop paying? Yes Read-only access, exports always available, nothing deleted before retention ends.