Security and data processing
Clear information for security evaluation.
Let's address the processed data, access responsibilities and service scope at the start of your evaluation process.
Data flow
Review the data flow together.
Clarify which data is sent to the service, which output is produced and the retention conditions within the contract scope. Assess storage location and data processing location separately.
- Data sent to the serviceRequired fields by check type
- Produced outputResult, source and review record
- Retention conditionsDefined within the contract scope
- Storage and processing locationAssessed separately
Operations
Access and operational scope.
We address your authorisation, record access, incident management and service continuity requirements in the technical evaluation. Discuss the required documents and the shareable scope with our team.
Authorisation
API credentials and user permissions; key revocation and scope.
Record access
Who accessed which record and for what purpose; no claim of immutable records.
Incident management and continuity
Incident notification, retry and service continuity requirements.
Verifiable documents
Verifiable documents.
When independent test or certificate information is provided, the related service, version, date and scope must be assessed together.
Data processing and privacy
Data processing and privacy.
How website, platform and service data is processed, stored encrypted, deleted and kept from being shared is explained in the Privacy Notice. Customer agreements additionally govern data processing terms, the region and the provider list.