> Pre-filled answers to common vendor-security-assessment questions, structured against the CSA CAIQ v4 domain taxonomy. EthicsPortal's positions on the questions procurement teams most often ask.

Source: https://ethicsportal.eu/bg/caiq/
Updated: 2026-08-24

---

# CAIQ-aligned vendor security questionnaire

EthicsPortal publishes pre-filled answers to the questions procurement teams most often ask. The questionnaire is structured against the Cloud Security Alliance's [CAIQ v4](https://cloudsecurityalliance.org/research/cloud-controls-matrix/) domain taxonomy --- the framework most EU enterprise procurement teams use --- so an evaluator can map this page directly into their existing assessment template.

This is a vendor-authored answer set, not an attestation by the CSA. The substance is what an external auditor would evaluate; the structure makes it easy to compare against vendors who have been audited.

A downloadable CSV is published at **[caiq-ethicsportal.csv](/caiq-ethicsportal.csv)** for ingestion into procurement tools.

Last updated: 2026-08-15.

---

## How to read this page

| Field | Meaning |
|---|---|
| Question | EthicsPortal's restatement of the question in the CAIQ domain |
| Answer | **Yes**, **No**, **Partially**, or **N/A**, with qualifiers where the substance is more useful than a binary --- for example **No (in treatment)** when a control is on the operator's roadmap, **Yes (inherited)** when a sub-processor's certification carries the control, **Yes (negative)** when the affirmative answer to a "does the Service do X?" question is "no, by design", or a specific value (24 hours, 99.5% monthly, Nuremberg) where one applies |
| Evidence | Link to the page or document that contains the substantive answer |

Where a question's answer is operationally sensitive (privileged-access mechanics, incident-response escalation contacts, infrastructure detail beyond what is on [/security/](/security/)), the answer here is **Available under NDA** and is shared during procurement review. This mirrors the posture published on [/trust/](/trust/#available-during-procurement-review).

---

## A&A --- Audit & Assurance

| ID | Question | Answer | Evidence |
|---|---|---|---|
| A&A-01 | Are independent audit or assurance assessments performed on the Service? | No (in treatment) | [ISO 27001 self-assessment](/iso-27001/) is published. External audit and penetration test are planned post-revenue and disclosed openly on [/trust/](/trust/#certification-status) |
| A&A-02 | Are audit reports available to customers? | No (in treatment) | When an independent audit or pen test is on record, scope, date, and remediation summary will be published on [/trust/](/trust/#certification-status) |
| A&A-03 | Does the organization conduct internal information security reviews? | Yes | [ISO 27001 Annex A control map](/iso-27001/) maintained as the structured self-assessment; reviewed annually |
| A&A-04 | Are compliance certifications listed publicly? | Yes | Certification status disclosed on [/trust/](/trust/#certification-status) (none currently held; structured self-assessment in place) |

---

## AIS --- Application & Interface Security

| ID | Question | Answer | Evidence |
|---|---|---|---|
| AIS-01 | Is application security testing performed? | Yes | Brakeman, bundler-audit, importmap audit on every change ([Security#secure-development-lifecycle](/security/#secure-development-lifecycle)) |
| AIS-02 | Is input validation enforced on all external inputs? | Yes | Rails framework defaults (strong parameters, output escaping); application-level checks at every controller boundary ([Security#secure-development-lifecycle](/security/#secure-development-lifecycle)) |
| AIS-03 | Is encryption applied to sensitive data at rest? | Yes | Non-deterministic Rails ActiveRecord Encryption on report content, reporter identity, communications, and attachments ([Security#data-encryption](/security/#data-encryption)) |
| AIS-04 | Is encryption applied to data in transit? | Yes | HTTPS/TLS for all connections; unencrypted HTTP redirected ([Security#data-encryption](/security/#data-encryption)) |
| AIS-05 | Is the application protected against OWASP Top 10 risks? | Yes | Framework-level defenses (parameterized queries, CSRF, output escaping, strong parameters, encrypted attributes); static analysis ([Security#secure-development-lifecycle](/security/#secure-development-lifecycle)) |

---

## BCR --- Business Continuity & Operational Resilience

| ID | Question | Answer | Evidence |
|---|---|---|---|
| BCR-01 | Is a documented business continuity plan in place? | Yes | [Business continuity plan](/policies/business-continuity/) |
| BCR-02 | Are backups encrypted? | Yes | Encrypted database dumps stored in Hetzner Object Storage; application-layer field encryption persists through the backup ([Security#backups-and-restore](/security/#backups-and-restore)) |
| BCR-03 | Are backup restores tested? | Yes | Quarterly restore drill into a disposable environment. Last drill date published on [Security#backups-and-restore](/security/#backups-and-restore) |
| BCR-04 | What is the recovery point objective (RPO)? | 24 hours | [SLA#recovery-objectives](/sla/#recovery-objectives) |
| BCR-05 | What is the recovery time objective (RTO)? | 4 hours | [SLA#recovery-objectives](/sla/#recovery-objectives) |
| BCR-06 | Is an availability target published? | Yes | 99.5% monthly for covered surfaces ([SLA](/sla/)) |
| BCR-07 | Is geographic redundancy in place across providers? | No | Backups are stored separately from compute within Hetzner; cross-provider redundancy not in place. Trade-off stated in [Risk register R-02](/policies/risk-register/) |

---

## CCC --- Change Control & Configuration Management

| ID | Question | Answer | Evidence |
|---|---|---|---|
| CCC-01 | Are changes managed through a documented process? | Yes | [Security#secure-development-lifecycle](/security/#secure-development-lifecycle) --- every change is checked against a written pre-deploy checklist, and the automated suite plus static analysis block the deploy on failure |
| CCC-02 | Is infrastructure managed as code? | Yes | Kamal deployment configuration version-controlled; no out-of-band production changes |
| CCC-03 | Are production and non-production environments separated? | Yes | Production is isolated; non-production environments use synthetic fixtures only ([Security#secure-development-lifecycle](/security/#secure-development-lifecycle)) |
| CCC-04 | Is there a documented vulnerability response timeline? | Yes | Critical 7 days, high 30 days, medium 90 days ([Security#secure-development-lifecycle](/security/#secure-development-lifecycle)) |

---

## CEK --- Cryptography, Encryption & Key Management

| ID | Question | Answer | Evidence |
|---|---|---|---|
| CEK-01 | Is data at rest encrypted? | Yes | Non-deterministic Rails ActiveRecord Encryption on all sensitive fields ([Security#data-encryption](/security/#data-encryption)) |
| CEK-02 | Is data in transit encrypted? | Yes | HTTPS/TLS; HTTP redirected |
| CEK-03 | Are customer-managed encryption keys (BYOK) supported? | No | Deliberate architectural choice; reporter--handler key boundary and end-to-end deletion guarantees require processor-managed keys ([DPA §6.11](/dpa/)) |
| CEK-04 | Are passwords stored using a one-way hash? | Yes | Reporter passcodes bcrypt-hashed and non-recoverable; handler/admin authentication via magic-link plus TOTP, no plaintext password storage |
| CEK-05 | Is encryption key management documented? | Yes | Key management follows the established Rails ActiveRecord Encryption lifecycle; keys are processor-managed and isolated from sub-processors ([Security#data-encryption](/security/#data-encryption)) |

---

## DCS --- Datacenter Security

| ID | Question | Answer | Evidence |
|---|---|---|---|
| DCS-01 | Where are data centers located? | Nuremberg, Germany (EU) | [Security#infrastructure](/security/#infrastructure) |
| DCS-02 | Are data centers under recognized physical-security certification? | Yes (inherited) | Hetzner data centers under Hetzner's certification scope ([ISO 27001 control map A.7](/iso-27001/#a7-physical-controls)) |
| DCS-03 | Is data residency limited to the EU/EEA? | Yes (core data) | Core application data, database, and file storage in Germany. One named non-EU sub-processor (Cloudflare, marketing-site CDN only) listed on [Subprocessors](/subprocessors/) |

---

## DSP --- Data Security & Privacy

| ID | Question | Answer | Evidence |
|---|---|---|---|
| DSP-01 | Is a Data Processing Agreement (DPA) available? | Yes | [DPA](/dpa/); signed countersigned copy on request to [legal@ethicsportal.eu](mailto:legal@ethicsportal.eu) |
| DSP-02 | Is the Service GDPR-compliant? | Yes | Processor under GDPR Art. 28; full coverage on [/directive-coverage/](/directive-coverage/) and [/dpa/](/dpa/) |
| DSP-03 | Are sub-processors publicly disclosed? | Yes | [Subprocessors](/subprocessors/) page lists each, with jurisdiction, purpose, and data categories |
| DSP-04 | How long is personal data retained? | Customer-configurable | 12, 24, 36, 48, or 60 months after report closure, with automatic deletion ([Security#audit-and-compliance](/security/#audit-and-compliance)) |
| DSP-05 | Is personal data deleted on customer request? | Yes | Within 30 days of subscription termination on written request ([DPA §6.8](/dpa/)) |
| DSP-06 | Is personal data minimization practiced? | Yes | Only essential fields are collected; reporter name and contact are optional. <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019L1937" target="_blank" rel="noopener noreferrer">Art. 5(1)(c)</a>
 GDPR ([Coverage map §7](/directive-coverage/#7-gdpr-compliance)) |
| DSP-07 | Is PII transmitted to any third party for processing? | Only to disclosed sub-processors | [Subprocessors](/subprocessors/) lists every recipient with the data category. No LLM or AI service is a sub-processor ([DPA §6.10](/dpa/)) |
| DSP-08 | Are data subjects' rights supported? | Yes | Access, rectification, erasure, restriction, portability, objection ([DPA §6.5](/dpa/)) |

---

## GRC --- Governance, Risk & Compliance

| ID | Question | Answer | Evidence |
|---|---|---|---|
| GRC-01 | Is there a published information security policy? | Yes | [Information security policy](/policies/information-security/) |
| GRC-02 | Is there a documented risk register? | Yes | [Risk register](/policies/risk-register/) |
| GRC-03 | Is risk assessed periodically? | Yes | Annually and on material change ([Risk register §Review-cadence](/policies/risk-register/)) |
| GRC-04 | Who owns information security at the organization? | Operator (named individual) | [IS policy §4](/policies/information-security/), [Trust#contracting-party](/trust/#contracting-party) |
| GRC-05 | Is regulatory compliance tracked? | Yes | GDPR, Directive 2019/1937, EAA / EN 301 549 ([Directive coverage map](/directive-coverage/), [Directive interpretations](/directive-interpretations/), [Accessibility](/accessibility/)) |

---

## HRS --- Human Resources Security

EthicsPortal has no employees or contractors. Personnel controls below are answered **N/A** with the compensating arrangements --- privileged-access summary available during procurement review, operator self-directed security awareness via subscribed feeds --- documented on [/trust/](/trust/#continuity-and-personnel) and in [ISO 27001 control map A.6](/iso-27001/#a6-people-controls).

| ID | Question | Answer | Evidence |
|---|---|---|---|
| HRS-01 | Are background checks performed on personnel with access to customer data? | N/A | No employees. Operator screening is verifiable through published registry information ([Trust#contracting-party](/trust/#contracting-party)) |
| HRS-02 | Is security awareness training provided to personnel? | N/A | No employees. Operator self-directed via Rails security mailing list, CVE feeds, advisory subscriptions |
| HRS-03 | Are confidentiality agreements in place for personnel? | N/A | No employees. Customer-side confidentiality is in [DPA §6.2](/dpa/) |
| HRS-04 | Is there a documented offboarding procedure for personnel with system access? | N/A | No employees. Customer offboarding is governed by [DPA §6.8](/dpa/) |

---

## IAM --- Identity & Access Management

| ID | Question | Answer | Evidence |
|---|---|---|---|
| IAM-01 | Is multi-factor authentication available for customer accounts? | Yes | TOTP-based 2FA for handler/admin accounts; reporter accounts use Case ID + bcrypt passcode (two-factor by construction) ([Security#access-control](/security/#access-control)) |
| IAM-02 | Is multi-factor authentication enforced on operator accounts with production access? | Yes | Hardware-key 2FA on all operator accounts with production access ([ISO 27001 A.8.2](/iso-27001/#a8-technological-controls)) |
| IAM-03 | Is role-based access control enforced? | Yes | Pundit policies enforced at every controller action; least-privilege defaults ([Security#access-control](/security/#access-control)) |
| IAM-04 | Are access rights reviewed periodically? | Yes | Member-deactivation lifecycle and audit-log review ([Security#member-access-and-offboarding](/security/#member-access-and-offboarding)) |
| IAM-05 | Is session management documented? | Yes | 14-day idle timeout; nightly sweep; per-session revocation ([Security#session-lifecycle](/security/#session-lifecycle)) |
| IAM-06 | Are passwords stored in plaintext? | No | Bcrypt for reporter passcodes; magic-link primary for handlers ([Security#access-control](/security/#access-control)) |

---

## IPY --- Interoperability & Portability

| ID | Question | Answer | Evidence |
|---|---|---|---|
| IPY-01 | Can customers export their data? | Yes | Self-service PDF case export in-product; machine-readable bulk export on request during exit ([DPA §6.8](/dpa/)) |
| IPY-02 | Are open data formats used for export? | Yes | PDF for case exports; machine-readable formats for bulk export under [DPA §6.8](/dpa/) |
| IPY-03 | Is API access available for portability? | No | Self-service PDF and bulk export are the documented portability surfaces |

---

## IVS --- Infrastructure & Virtualization Security

| ID | Question | Answer | Evidence |
|---|---|---|---|
| IVS-01 | Is the Service multi-tenant? | Yes | Multi-tenant at the application layer; isolation enforced by Pundit policies and per-organization scoping at every controller action ([Security#access-control](/security/#access-control)) |
| IVS-02 | Is network segmentation in place? | Yes | Production isolated from operator workstation by network boundary; non-production environments hold no production personal data ([Security#secure-development-lifecycle](/security/#secure-development-lifecycle)) |
| IVS-03 | Is malware protection in place for uploaded content? | Yes | ClamAV virus scanning on all uploads before delivery ([Security#virus-scanning](/security/#virus-scanning)) |

---

## LOG --- Logging and Monitoring

| ID | Question | Answer | Evidence |
|---|---|---|---|
| LOG-01 | Are user actions logged? | Yes | Append-only audit trail with timestamp, actor, and action type ([Security#audit-and-compliance](/security/#audit-and-compliance)) |
| LOG-02 | Are logs tamper-evident? | Partially | PostgreSQL triggers reject changes to core audit content and table truncation, and application users cannot edit or selectively delete individual entries. The trail is not hash-chained or WORM-backed, so privileged database intervention remains a documented residual risk ([Risk register R-08](/policies/risk-register/#r-08-audit-log-integrity-compromise)) |
| LOG-03 | How long are audit logs retained? | Customer-configurable | Matches case retention (12/24/36/48/60 months); included in PDF case exports for regulatory review |
| LOG-04 | Is application monitoring in place? | Yes | AppSignal instruments the application with session-data transmission disabled and request parameters filtered to preserve reporter anonymity ([Subprocessors](/subprocessors/)) |
| LOG-05 | Are clocks synchronized? | Yes | NTP via host OS; all timestamps recorded in UTC |

---

## SEF --- Security Incident Management

| ID | Question | Answer | Evidence |
|---|---|---|---|
| SEF-01 | Is a documented incident response plan in place? | Yes | [Business continuity plan §3--5](/policies/business-continuity/) and the [Incident register](/incidents/) disclosure timeline |
| SEF-02 | Are customers notified of personal data breaches? | Yes | Without undue delay, in any case within 72 hours of awareness ([DPA §6.6](/dpa/)) |
| SEF-03 | Is a public incident register maintained? | Yes | [Incident register](/incidents/) |
| SEF-04 | What is the timeline for incident disclosure? | Tiered | Customers: 72h of awareness; preliminary register entry: 7d post-containment; final entry: 30d post-containment ([Incident register](/incidents/)) |
| SEF-05 | Is there a responsible-disclosure inbox? | Yes | [security@ethicsportal.eu](mailto:security@ethicsportal.eu) ([Security#responsible-disclosure](/security/#responsible-disclosure)) |

---

## STA --- Supply Chain Management, Transparency & Accountability

| ID | Question | Answer | Evidence |
|---|---|---|---|
| STA-01 | Is a sub-processor list published? | Yes | [Subprocessors](/subprocessors/) with per-row data category, jurisdiction, purpose |
| STA-02 | Are customers notified before sub-processors are added or replaced? | Yes | At least 30 days advance notice ([DPA §6.4](/dpa/)) |
| STA-03 | Can customers object to a sub-processor change? | Yes | Right to terminate if no resolution is reached ([DPA §6.4](/dpa/)) |
| STA-04 | Are sub-processors bound by data-protection agreements? | Yes | Written DPA in place with each sub-processor under GDPR Art. 28 |
| STA-05 | Is AI or LLM processing of customer data disclosed? | Yes (negative) | No LLM, generative-AI, or AI-classifier service is engaged as a sub-processor or used to process report content ([DPA §6.10](/dpa/), [Coverage map §5](/directive-coverage/#5-confidentiality-of-identity-art-16)) |
| STA-06 | Are international data transfers documented? | Yes | Standard Contractual Clauses + safeguards for the single named non-EU sub-processor ([Subprocessors](/subprocessors/), [DPA §7](/dpa/)) |

---

## TVM --- Threat & Vulnerability Management

| ID | Question | Answer | Evidence |
|---|---|---|---|
| TVM-01 | Are dependencies scanned for vulnerabilities? | Yes | Brakeman (Rails), bundler-audit (Ruby), importmap audit (JavaScript) on every change ([Security#dependency-and-patch-management](/security/#dependency-and-patch-management)) |
| TVM-02 | Is a vulnerability disclosure program in place? | Yes | [Responsible disclosure](/security/#responsible-disclosure) with documented acknowledgement and remediation SLAs |
| TVM-03 | What is the remediation SLA for vulnerabilities? | Tiered | Critical 7 days, high 30 days, medium 90 days ([Security#secure-development-lifecycle](/security/#secure-development-lifecycle)) |
| TVM-04 | Are penetration tests performed? | No (in treatment) | None currently on record; planned post-revenue ([Trust#certification-status](/trust/#certification-status), [ISO 27001 A.5.35](/iso-27001/#a5-organizational-controls)) |

---

## UEM --- Universal Endpoint Management

| ID | Question | Answer | Evidence |
|---|---|---|---|
| UEM-01 | Are operator endpoints hardened? | Yes | Operator workstation: full-disk encryption, screen-lock, OS auto-update, hardware-key 2FA on production-access accounts ([ISO 27001 A.8.1](/iso-27001/#a8-technological-controls)) |
| UEM-02 | Are mobile devices used for production access? | No | Production access is restricted to the operator's primary workstation |
| UEM-03 | Is a clear-desk and clear-screen policy in place? | Self-assessed | Operator workstation has automatic screen-lock; clear-desk practice for any printed materials ([ISO 27001 A.7.7](/iso-27001/#a7-physical-controls)) |

---

## Available under NDA during procurement review

The following operational topics are not in this public questionnaire because they contain infrastructure and response detail that is more appropriate for controlled disclosure. They are shared on request during procurement review:

- Privileged production-access mechanics (specific accounts, hardware-key type, escalation paths)
- Incident-response escalation contacts and on-call rotation
- Business-continuity contact tree
- Internal vulnerability-response tracker contents
- Restore-drill artefacts and timing detail beyond the date

To request these materials, contact [support@ethicsportal.eu](mailto:support@ethicsportal.eu).

---

## Document control

| Field | Value |
|---|---|
| Document title | EthicsPortal CAIQ-aligned vendor security questionnaire |
| Structure | CSA CAIQ v4 domain taxonomy (Audit & Assurance through Universal Endpoint Management) |
| Version | 1.0 |
| Effective date | 2026-05-21 |
| Last reviewed | 2026-05-21 |
| Next scheduled review | 2027-05-21 |
| Owner | Yaroslav Shmarov, operator |
| Machine-readable copy | [caiq-ethicsportal.csv](/caiq-ethicsportal.csv) |
