For the chief information security officer

The two gaps, before anything else on this page

A SOC 2 Type II attestation is in progress and no report exists that we could hand you. We hold neither a FedRAMP authorization nor a FedRAMP certification, and no equivalency is claimed. If either is a hard gate in your programme, decline now — you will not find a better answer further down, and you should not have to spend six weeks discovering that.

What the job actually is, as distinct from what it is described as

You approve things you did not choose, on a timeline set by somebody whose bonus depends on the deal closing, using evidence supplied by the counterparty. The sponsor has already told the executive team it is happening. Your review is characterised internally as diligence and experienced internally as an obstacle, and both of those are said about you in the same meeting.

The asymmetry is total. A vendor knows their own weaknesses precisely and controls which of them reach you. You get a questionnaire returned by somebody who skim-read it, an architecture diagram drawn for persuasion, and a list of frameworks with no indication of which are held, which are aspirations and which are somebody else’s.

Then artificial intelligence arrived and added a category of exposure nobody had a control mapped to. A prompt is an egress path. A model provider is a third party who now receives your text. Retention at that provider is a contractual question most buyers never think to ask, and most vendors are not eager to raise. Meanwhile the executive mandate is to adopt quickly.

And the scoring is asymmetric in a way that shapes everything. Ninety-nine correct approvals are invisible. One breach is a board conversation, a regulatory notification, and in some sectors the end of a career. Caution is rational under that scoring, which is exactly why a vendor who makes caution expensive is telling you something about themselves.

The gap you cannot close from a vendor page

You are asked to certify a risk position using evidence the counterparty selected, on a schedule you did not set, for a technology whose newest exposure has no established control mapping.

Nothing on any vendor website solves that, including this one. What a page can do is refuse to make it worse — by stating the absences first, by marking every framework with its actual status, and by answering the questions that are usually left for you to think of.

So here are the ones most often missing. Where does a prompt go: to whichever model provider is configured for your deployment, and you can require that to be your own account under your own contract, in which case the text goes to a provider you already have terms with and we hold no credential of yours. What is retained: what your configuration says is retained, and where a third-party provider is in the path, their retention terms govern that leg and we will name the provider rather than describe it as a partner.

Tenancy, isolation, identity and audit each have their own page in this set, written for your team rather than for you, and each states a limit before it states a capability. This page does not restate them, because a restatement is where the caveat goes missing.

The last thing, and it is the one we would want a reviewer to weigh: we will not sign a clause requiring deletion from an already-written backup image, because that is not a thing our architecture can do and a supplier who signs it is either mistaken or intends not to comply. That refusal costs us deals. It is on the page anyway.

What changes about your review, not about your risk

How early a disqualifying fact reaches you — measured by stage at which it surfaces — the first screen of the first page is the target here.

Whether framework status is legible without interpretation — measured by each line marked held, in progress, operating, applicability-gated or designed for.

How many rounds a questionnaire takes to become usable — measured by return trips before your team stops asking follow-up questions.

Whether the egress path is a known quantity — measured by named provider, named account holder, named retention terms, before signature.

Whether you can investigate without asking the vendor — measured by audit events reaching your own collection point on your own schedule.

How much of the approval rests on trusting us — measured by proportion of controls you can verify yourself against ones you must take on assertion.

that your risk decreases. A new supplier is new exposure and this page does not pretend otherwise. What it claims is that the exposure is legible earlier and stated more completely than a review process usually permits.

What your security operations centre gets

Evidence goes where you already look. Authentication events, authority grants, action receipts and configuration changes stream to your existing collection point, so an investigation runs on your timeline rather than on our support queue’s.

Identity federates to your provider. There is no parallel account population to review separately and no second joiner-mover-leaver process to keep synchronised, which removes an entire class of stale-entitlement finding rather than mitigating it.

Where you bring your own model provider, the credential stays yours. We hold platform-level integration identifiers and a master key for what we encrypt; the per-account credential belongs to your organisation and can be revoked by your organisation without asking us.

Each of these is checkable, and two of them are refusals

A claim you cannot check is a claim you should discount. Every line below says where to go, and where the honest answer is that something is designed rather than attested, it says that word instead of a stronger one.

The refusals are listed alongside the capabilities deliberately. A security position with no stated limits has either not been examined or is not being fully described, and you already know which is more common.

The package, and the questions it will not dodge

Ask for what your assessment actually needs. Sending the complete set to a reviewer who asked one tenancy question is a way of appearing thorough while consuming the attention you were trying to respect.

Where a document does not exist, that is said on the first response rather than the third, and the reason is given. A supplier who takes three rounds to admit an absence has told you how the next question will go.

Approve something small enough to be wrong about

One queue, one workflow, low data sensitivity, with the stop conditions written down before it starts — sized so that being wrong costs a scope rather than a notification.

The strongest thing you can do is not a longer questionnaire. It is bounding the first engagement so that a mistaken approval is survivable, and writing the stop conditions down in advance. Recorded beforehand they are criteria. Raised afterwards they are a dispute you will lose to the deal timeline.

Pick a scope where the data is genuinely low sensitivity. Not because the controls are weaker there, but because it lets you observe our behaviour under a real workload before you have to be right about it — how an incident is communicated, how quickly an unknown gets marked as unknown, whether the escalation contact answers.

And require the egress decision at the start. Which provider, whose account, whose retention terms. That question is cheap to answer before signature and expensive to reopen after.

Questions buyers actually ask

No SOC 2 report is a hard gate for us. This conversation is over.

Then it is over, and that is a legitimate outcome we would rather reach on the first page than in week six. The attestation is in progress and the observation window has to run; no contracting language and no compensating control substitutes for the report. If your policy has a documented exception path for a bounded low-sensitivity scope, that is the only conversation left worth having, and if it does not, declining is correct.

Where does our text actually go when the model runs?

To whichever model provider is configured for your deployment, and you can require that to be your own account under your own contract — in which case the text goes to a provider you already hold terms with, their retention governs that leg, and we hold no credential of yours. Where it runs against our configuration instead, the provider is named rather than described as a partner, and the retention position is stated. That question decides more of your exposure than most of the questionnaire and it is asked far too rarely.

Your compliance list is shorter than the incumbent proposal on my desk.

It is shorter because every line carries its actual status and nothing is marked as held. Before comparing lengths, check whether the other list separates held certifications from in-progress assessments from architectural intentions. If it does not, you are comparing an annotated list against an unannotated one, which is not a comparison — it is a length contest between different units.

We require contractual deletion from backups within thirty days.

We will not sign that, and the reason is that our architecture cannot do it: a backup image is written once and restored whole, so a per-record deletion inside it is not a capability we could perform on request. What we will commit to is deletion from live systems on a defined timeline and expiry of the backup images themselves on a stated retention schedule. A supplier who signs the clause as you have written it is either mistaken about their own architecture or does not intend to comply, and you would rather learn which one now.

How do I know any of this is true rather than well written?

Mostly you do not, yet, and that is the honest answer — which is why the page marks designed as designed rather than borrowing a stronger word. What you can verify independently: that the audit events actually reach your collection point during a bounded first scope, that an unknown gets marked unknown on the first response instead of the third, and that the named escalation contact answers. Those are cheap to test and they predict the rest better than any document does.