| 1 | Is customer data encrypted at rest? | Yes. All customer data is encrypted at rest. | Confirmed | security_whitepaper#infrastructure |
| 2 | Is data encrypted in transit? | Yes. All traffic uses TLS. | Confirmed | security_whitepaper#practices |
| 3 | Do you enforce multi-factor authentication for staff? | Yes, for all staff accounts. | Confirmed | access_control_policy#authentication |
| 4 | Where is customer data hosted? | In the EU, on Microsoft Azure (Frankfurt). | Confirmed | security_whitepaper#infrastructure |
| 5 | Do you have a documented incident response process? | Yes. A written runbook, tested twice a year. | Confirmed | incident_response_policy#process |
| 6 | How long do you retain customer data after termination? | 90 days after the contract ends, then deleted. | Confirmed | retention_schedule#table |
| 7 | Do you use subprocessors? | Yes. The current list is published with our DPA. | Confirmed | subprocessor_list#table |
| 8 | Will you notify us of new subprocessors? | Yes, in advance, as set out in the DPA. | Confirmed | dpa#subprocessors |
| 9 | Who is your privacy contact? | privacy@tallowfinch.example | Confirmed | privacy_policy#controller |
| 10 | Do you sign a data processing agreement? | Yes. Our DPA follows Article 28 UK GDPR. | Confirmed | dpa#gdpr_art28 |
| 11 | How do you handle data subject requests? | Through a documented procedure with a one-month response target. | Confirmed | dsar_procedure#handling |
| 12 | Is production access restricted? | Yes, to named engineers with just-in-time access. | Confirmed | access_control_policy#production_access |
| 13 | Do you export data on termination? | Yes, on request before deletion. | Confirmed | dpa#termination |
| 14 | Do you process special category data? | No. | Confirmed | privacy_policy#data_collected |
| 15 | Do you process children's data? | No. | Confirmed | privacy_policy#data_collected |
| 16 | Where are your customers located? | The United Kingdom, Germany and the Netherlands. | Confirmed | privacy_policy#controller |
| 17 | Do you perform background checks on employees? | Drafted from general policy wording; please confirm with HR. | Check | — |
| 18 | How often do you review access rights? | Access is reviewed when roles change; the review cadence is not documented. | Check | — |
| 19 | Do you have a business continuity plan? | A plan exists in outline; testing frequency needs confirmation. | Check | — |
| 20 | Do you classify data by sensitivity? | Customer data is treated as confidential; a formal scheme is not documented. | Check | — |
| 21 | Do you have cyber insurance? | Outside the scope of the documents; please confirm. | Check | — |
| 22 | Have you had an independent penetration test in the last 12 months? | Not currently in place. Planned; timing to be confirmed. | Gap | — |
| 23 | Do you hold ISO 27001 certification? | Not currently in place. | Gap | — |
| 24 | Do you run security awareness training for all staff? | Not currently in place. Planned; timing to be confirmed. | Gap | — |