Trust Center

Security questionnaires, already answered

Your security team does not need to wait on us. The CAIQ and SIG Lite response sets, the SOC 2 control matrix, the subprocessor list and the penetration-test status are written, evidenced against the codebase, and ready to send.

Released on request to a named reviewer · Every document in the pack is reviewed before it is sent.

01

What is in the pack

Seven documents, each written against the current state of the platform rather than a roadmap, and each citing the file or configuration that evidences it.

CAIQ (CSA Cloud Controls Matrix domains)

Pre-filled responses across the CSA CCM v4 domains, each answer carrying its evidence.

SIG Lite questionnaire

Pre-filled SIG Lite responses across governance, access, encryption, infrastructure, SDLC, logging, incident response, continuity, privacy and vendor management.

Security and compliance statement

The narrative statement of how the platform protects customer data, written to the current state rather than the roadmap.

SOC 2 control matrix and gap register

The technical control audit mapped to the SOC 2 Trust Services Criteria, with the maintained gap register.

SOC 2 roadmap

Where attestation actually stands: what is complete, what is in progress, and what has not started.

Penetration test status

The current third-party testing position and the internal security audits that exist instead.

Subprocessor list

Every service provider that may process customer or contact data, with purpose, data categories and region.

Information security policy

The apex policy: ISMS scope, the security owner, the subordinate policy set, the exception process and the review cadence.

Access control policy and access review procedure

How logical access is granted, reviewed and revoked across the cloud estate, the repositories, the application roles and the vendor consoles.

Joiner, mover and leaver procedure

Per-system provisioning and deprovisioning steps with named performer roles and a maximum time from departure to revocation.

Risk management policy and risk register

The scored register of security risks with owners and treatment decisions, derived from the control gap register rather than a template.

Business continuity and disaster recovery plan

Recovery objectives, the scenario-to-runbook map, invocation authority, and the rehearsal schedule with its current status.

Secure development and change management policies

The development lifecycle as it actually runs: review requirements, the CI guard suite, environment separation, deployment and rollback.

Vendor risk management policy

How third parties are tiered by the data they can reach, what each tier must evidence before onboarding, and the re-assessment cadence.

Data classification and handling policy

The classification tiers applied to the data this platform actually holds, with the handling rule for each tier.

Cryptography policy

Algorithms in use, key management through the cloud secret store, rotation cadence, and the honest position on what is not encrypted.

Human resources security policy and training programme

Screening, terms of engagement, onboarding and offboarding security steps, and the awareness training programme with its record.

Logging and monitoring policy

What is logged, what is redacted, how long records are kept, what alerts exist and who reviews them.

AI management policy and AI system inventory

The AI management system: every AI-using surface, the data that enters each prompt, the human approval points, and the product boundaries enforced in code.

02

The answers that usually end a deal, up front

These are the questions worth knowing before you spend a call on us. We would rather you disqualify us early than discover this in week three.

CAIQ (CSA Cloud Controls Matrix domains)

Sagaris holds no third-party attestation.

SIG Lite questionnaire

No SOC 2, ISO 27001 or equivalent attestation is held.

Security and compliance statement

Planned-but-absent capabilities are stated as absent.

SOC 2 control matrix and gap register

It maps repository-evidenced technical controls, not organizational controls.

SOC 2 roadmap

No SOC 2 report exists and Sagaris must not be described as SOC 2 certified.

Penetration test status

No third-party penetration test has been conducted.

Subprocessor list

Several subprocessors are optional and process data only when you enable the integration.

03

Why it is on request

Because the pack is honest, it names the controls that are partial and the ones that are not in place yet. Published openly, that is a ranked list of where to attack us, maintained by us, with dates. Sent to a named reviewer, it is what it is meant to be: evidence for a security review.

We do not put it behind a login, because your security team has no account with us yet, and a wall you cannot get through is not a control, it is a lost deal. Ask, and a named person sends it.

04

Request the pack

Tell us which questionnaire your team uses and we will send the matching response set. If you have your own template, send it and we will fill it from the same evidence rather than writing new answers.

Contact us
Book a demo