Skip to main content

Vendor readiness

Procurement should not have to reconstruct the firm from scattered claims.

The diligence packet connects the contracting entity, operating owners, assurance evidence, data boundaries, provider register, insurance, continuity, and engagement-specific decision record.

ForPeople conducting policy, privacy, security, or access review

FocusControls, ownership, evidence, and review paths

Core diligence packet

Table — scroll horizontally to review every column.

AreaCurrent evidence
Company and ownershipEntity details, leadership roles, disclosures, and authorized signatories
SecuritySOC 2 Type II report; April 2026 penetration-test summary; control narratives
Privacy and dataData-flow, retention, deletion, region, access, and incident records
Insurance$5 million technology E&O; $5 million cyber liability
DeliveryFrame → Assemble → Govern → Transfer; named decision owners; acceptance and handoff records
PeopleNamed proposed specialists, Rigors evidence, direct client review, and role-specific controls
ProvidersCurrent subprocessor register, change process, monitoring, and exit plan
AccessibilityWCAG 2.1 AA review completed July 14, 2026

Engagement-specific review

The common packet is the starting point. Each engagement then records the actual systems, data, regions, providers, access, client approvals, contractual responsibilities, evidence, and transfer conditions that apply to that work.

Open the Trust Center

Request the diligence packet.