Trust · SIG-Lite

Shared Assessments SIG-Lite v1.0

Pre-filled responses to the Shared Assessments SIG-Lite v1.0 standardised vendor-risk questionnaire. Drop-in for vendor onboarding.

← back to /trust

FieldResponse
Audit log retention7 years. CFTC 1.31 / SEC 17a-4. Anchored to audit_log table, anon DENY, service-role write only.
Data Processing AddendumGDPR Art. 28 DPA. Standard Contractual Clauses Module Two.
Data residencyEU-Central-1 (Frankfurt) for Postgres + backups. Optional eu-central-1 Bedrock for AI inference.
Encryption in transit / at restTLS 1.3 / AES-256.
Authentication factorsWorkOS SAML 2.0 + SCIM 2.0 for enterprise. MFA required across all admin paths.
Code quality controlsTypeScript strict, Zod input validation, Dependabot, `pnpm audit` weekly.
Logging & monitoringSentry runtime error capture. Vercel runtime logs. Per-service health endpoints surface to /status.
Email vendorResend.
Billing vendorStripe Checkout + Customer Portal.
Identity vendorWorkOS (SAML 2.0 + SCIM 2.0).
AI inference vendorAnthropic (claude-opus-4-7). Bedrock optional for on-prem.
Vulnerability disclosure policysecurity@edgefx.xyz — 90-day coordinated disclosure window.
Breach notification SLA72 hours per GDPR Art. 33.
Right to be forgottenGDPR Art. 17. Account deletion within 30 days; audit_log rows anonymised, not deleted (regulatory retention).