Security and data processing

Clear information for security evaluation.

Let's address the processed data, access responsibilities and service scope at the start of your evaluation process.

Data flow

Review the data flow together.

Clarify which data is sent to the service, which output is produced and the retention conditions within the contract scope. Assess storage location and data processing location separately.

  • Data sent to the serviceRequired fields by check type
  • Produced outputResult, source and review record
  • Retention conditionsDefined within the contract scope
  • Storage and processing locationAssessed separately

Operations

Access and operational scope.

We address your authorisation, record access, incident management and service continuity requirements in the technical evaluation. Discuss the required documents and the shareable scope with our team.

Authorisation

API credentials and user permissions; key revocation and scope.

Record access

Who accessed which record and for what purpose; no claim of immutable records.

Incident management and continuity

Incident notification, retry and service continuity requirements.

Verifiable documents

Verifiable documents.

When independent test or certificate information is provided, the related service, version, date and scope must be assessed together.

Data processing and privacy

Data processing and privacy.

How website, platform and service data is processed, stored encrypted, deleted and kept from being shared is explained in the Privacy Notice. Customer agreements additionally govern data processing terms, the region and the provider list.