Security questionnaires, already answered
Your security team does not need to wait on us. The CAIQ and SIG Lite response sets, the SOC 2 control matrix, the subprocessor list and the penetration-test status are written, evidenced against the codebase, and ready to send.
Released on request to a named reviewer · Every document in the pack is reviewed before it is sent.
What is in the pack
Seven documents, each written against the current state of the platform rather than a roadmap, and each citing the file or configuration that evidences it.
CAIQ (CSA Cloud Controls Matrix domains)
Pre-filled responses across the CSA CCM v4 domains, each answer carrying its evidence.
SIG Lite questionnaire
Pre-filled SIG Lite responses across governance, access, encryption, infrastructure, SDLC, logging, incident response, continuity, privacy and vendor management.
Security and compliance statement
The narrative statement of how the platform protects customer data, written to the current state rather than the roadmap.
SOC 2 control matrix and gap register
The technical control audit mapped to the SOC 2 Trust Services Criteria, with the maintained gap register.
SOC 2 roadmap
Where attestation actually stands: what is complete, what is in progress, and what has not started.
Penetration test status
The current third-party testing position and the internal security audits that exist instead.
Subprocessor list
Every service provider that may process customer or contact data, with purpose, data categories and region.
Information security policy
The apex policy: ISMS scope, the security owner, the subordinate policy set, the exception process and the review cadence.
Access control policy and access review procedure
How logical access is granted, reviewed and revoked across the cloud estate, the repositories, the application roles and the vendor consoles.
Joiner, mover and leaver procedure
Per-system provisioning and deprovisioning steps with named performer roles and a maximum time from departure to revocation.
Risk management policy and risk register
The scored register of security risks with owners and treatment decisions, derived from the control gap register rather than a template.
Business continuity and disaster recovery plan
Recovery objectives, the scenario-to-runbook map, invocation authority, and the rehearsal schedule with its current status.
Secure development and change management policies
The development lifecycle as it actually runs: review requirements, the CI guard suite, environment separation, deployment and rollback.
Vendor risk management policy
How third parties are tiered by the data they can reach, what each tier must evidence before onboarding, and the re-assessment cadence.
Data classification and handling policy
The classification tiers applied to the data this platform actually holds, with the handling rule for each tier.
Cryptography policy
Algorithms in use, key management through the cloud secret store, rotation cadence, and the honest position on what is not encrypted.
Human resources security policy and training programme
Screening, terms of engagement, onboarding and offboarding security steps, and the awareness training programme with its record.
Logging and monitoring policy
What is logged, what is redacted, how long records are kept, what alerts exist and who reviews them.
AI management policy and AI system inventory
The AI management system: every AI-using surface, the data that enters each prompt, the human approval points, and the product boundaries enforced in code.
The answers that usually end a deal, up front
These are the questions worth knowing before you spend a call on us. We would rather you disqualify us early than discover this in week three.
CAIQ (CSA Cloud Controls Matrix domains)
Sagaris holds no third-party attestation.
SIG Lite questionnaire
No SOC 2, ISO 27001 or equivalent attestation is held.
Security and compliance statement
Planned-but-absent capabilities are stated as absent.
SOC 2 control matrix and gap register
It maps repository-evidenced technical controls, not organizational controls.
SOC 2 roadmap
No SOC 2 report exists and Sagaris must not be described as SOC 2 certified.
Penetration test status
No third-party penetration test has been conducted.
Subprocessor list
Several subprocessors are optional and process data only when you enable the integration.
Why it is on request
Because the pack is honest, it names the controls that are partial and the ones that are not in place yet. Published openly, that is a ranked list of where to attack us, maintained by us, with dates. Sent to a named reviewer, it is what it is meant to be: evidence for a security review.
We do not put it behind a login, because your security team has no account with us yet, and a wall you cannot get through is not a control, it is a lost deal. Ask, and a named person sends it.
Request the pack
Tell us which questionnaire your team uses and we will send the matching response set. If you have your own template, send it and we will fill it from the same evidence rather than writing new answers.