The 10 questions a F500 vendor-risk reviewer asks first, with verbatim answers + verification paths. The shape mirrors SIG / VSA / CAIQ row-shape so a procurement reviewer copies answers row-for-row instead of paraphrasing.
Are SOC 2 Type II reports issued by an independent registered auditor for the platform infrastructure?
Class · controlYes. Vercel (application hosting + edge compute) — SOC 2 Type II by Insight Assurance, AICPA-registered, continuous rolling 12-month observation window. Supabase (Postgres + Auth + file storage) — SOC 2 Type II + HIPAA by Prescient Assurance, AICPA-registered, continuous rolling 12-month window. Both reports cover the platform on which Decision Intel runs.
Verification: vercel.com/legal/soc2 · supabase.com/security · trust portals public
Does the application processor itself hold a SOC 2 attestation?
Class · controlDecision Intel’s product-level SOC 2 Type I audit is targeted Q4 2026 issuance, with the Type II observation window opening immediately after. Audit firm to be named at engagement (Big-4 or AICPA-listed Tier-1 specialist). In-flight controls already mirror Type II requirements; the gap between today and Type I issuance is documented in the Enterprise pilot agreement.
Verification: Status disclosed in writing on every Enterprise pilot agreement.
Is data encrypted at rest and in transit?
Class · dataYes. AES-256-GCM for documents and audit-log content at rest. TLS 1.2+ for every transit hop (browser to platform, platform to AI providers, platform to sub-processors). A GDPR + NDPR anonymization layer strips PII before any AI processing — the LLM provider never sees raw customer content with identifiers attached.
Verification: /privacy data lifecycle section · processor list with sub-processor details
What is the audit log retention window?
Class · dataIndividual tier: 1 year. Strategy tier (team): 3 years. Enterprise tier: 7 years (SOX §404 internal-controls aligned). Every entry is immutable, append-only, and timestamped at write. Entries are queryable via the customer-facing AdminAuditLog UI and exportable as a single JSON bundle via the Enterprise account-data export endpoint. Custom retention (HIPAA, banking, government) is negotiable on Enterprise pilot agreement.
Verification: /security audit-log retention SLA section · contractual commitment in pilot agreement.
What is the disaster recovery posture (RPO / RTO)?
Class · continuityRecovery Point Objective ≤ 15 minutes (Postgres WAL streaming + daily snapshots). Recovery Time Objective < 4 hours. Production region is US (Vercel + Supabase US). EU region is available on Enterprise pilot agreement; multi-region production is on the published roadmap. Annual restore drill is performed and documented; the most recent drill date is disclosed on every Enterprise pilot agreement.
Verification: /security DR/BCP section · drill date in pilot agreement.
What is the security-incident response SLA?
Class · incidentCustomer notification within 72 hours of confirmed security incident affecting customer data — mirrors GDPR Art. 33 controller-notification timing as the procurement floor. Faster notification (24 hours / 12 hours) is negotiable on Enterprise pilot agreement when the customer’s own regulatory posture requires it. A written incident report is delivered within 7 days of notification, including root cause, scope of affected records, remediation steps, and the controls hardened to prevent recurrence.
Verification: Pilot agreement · incident report template available on request.
What is the standard liability cap?
Class · contractual12 months of fees paid by Controller in the 12 months immediately before the claim, excluding (a) breach of confidentiality, (b) wilful misconduct, (c) third-party IP indemnities, and (d) sub-processor data-protection failures where Decision Intel is the engaging Processor. Mutual indemnification cap and uncapped third-party-IP indemnity are negotiable at Enterprise signature.
Verification: Subscription agreement § 12 · Enterprise pilot indemnification schedule.
Is cyber-liability insurance and errors-and-omissions insurance carried?
Class · contractualOn the Q1 2027 roadmap. Until carriage is live, Enterprise customers receive a written disclosure of the insurance gap and the contractual commitments that substitute for it (uncapped breach-of-confidentiality, mutual indemnification, escrowed remediation budget on request).
Verification: Enterprise pilot agreement · insurance gap disclosure clause · roadmap status updated quarterly.
Where is customer data trained on for AI improvements?
Class · dataCustomer document content is never used to train, fine-tune, or evaluate any LLM (Gemini, Claude, or otherwise). Provider terms (Google Cloud Platform + Anthropic) explicitly disclaim training on enterprise inputs. The same commitment is mirrored in the DPA and every pilot agreement. Bias Genome cohort signals are derived from outcome METADATA only (bias type, decision-domain class, predicted-vs-realised quality, time-to-outcome window) — never document content, persona names, or deal terms.
Verification: DPA § Bias Genome ownership · provider terms (GCP + Anthropic enterprise DPA).
What is the data portability and exit-assistance posture on contract termination?
Class · dataCustomer-owned content (every uploaded artefact + every Decision Provenance Record) is exportable as a single account-data JSON bundle at any time during the contract and within 60 days of termination. Cohort export (anonymised outcome metadata the customer organisation contributed to Bias Genome) is available on quarterly cadence on Enterprise tier. After the 60-day exit window, customer content is cryptographically destroyed; audit log entries follow the retention window above.
Verification: /api/export/account · DPA § 5 · pilot agreement termination clause.