Security & Compliance
Supplier Security Requirements
All technology suppliers and subprocessors engaging with SecuryxAI must meet these baseline security requirements.
Scope: These requirements apply to all third-party suppliers, technology vendors, and subprocessors who process, store, transmit, or have logical or physical access to SecuryxAI systems or customer data. Suppliers must attest to compliance with these requirements prior to onboarding and annually thereafter.
Overview
SecuryxAI operates a GRC platform that customers rely on for sensitive compliance data. The security of our supply chain directly affects the security posture we can offer our customers. These requirements are derived from industry standards including ISO 27001, SOC 2 Trust Services Criteria, and the NIST Cybersecurity Framework.
Access Control
- Multi-factor authentication (MFA) required for all staff with access to systems that process SecuryxAI or customer data
- Principle of least privilege enforced — access provisioned on a need-to-know basis
- Privileged access management (PAM) for administrative access to production systems
- Access reviews conducted at minimum every 6 months
- Prompt de-provisioning of access within 24 hours of role change or termination
Encryption
- All data in transit encrypted using TLS 1.2 or higher (TLS 1.3 preferred)
- All data at rest encrypted using AES-256 or equivalent
- Encryption keys managed using a dedicated key management service (not stored alongside encrypted data)
- Mobile device management (MDM) enforced encryption on all endpoints handling sensitive data
- Prohibition on storing sensitive data in plaintext in logs, cache, or temporary files
Vulnerability Management
- Formal vulnerability management programme with defined SLAs: Critical ≤24h, High ≤7 days, Medium ≤30 days
- Dependency scanning integrated into CI/CD pipeline
- Annual penetration test by a qualified third party; results shared with SecuryxAI on request
- Vulnerability disclosure programme or bug bounty in place
- Operating systems and software maintained on supported versions with security patches applied promptly
Incident Notification
- Notification to SecuryxAI within 24 hours of discovering a security incident that involves SecuryxAI data or systems
- Incident report provided within 72 hours containing: nature of incident, data affected, remediation steps taken
- Designated security contact available 24/7 during active incidents
- Post-incident review (root cause analysis) provided within 30 days for significant incidents
- No suppression or delay of incident notification regardless of ongoing investigation
Data Handling
- SecuryxAI data processed only for the documented purpose of service delivery — no secondary use for training, analytics, or marketing
- Data minimisation: collect and retain only what is necessary for the contracted service
- Data retention limits aligned with SecuryxAI DPA — no indefinite retention of processing outputs
- Documented data mapping covering where SecuryxAI data is stored, processed, and transmitted
- Secure deletion of SecuryxAI data within 30 days of contract termination (certificate of destruction on request)
- Sub-processing of SecuryxAI data requires advance written approval
Audit & Compliance
- SOC 2 Type II report or equivalent (ISO 27001 certification) required for suppliers processing personal data
- Security questionnaire completion (SIG Lite or equivalent) within 30 days of onboarding
- Annual re-certification: updated SOC 2 report, security questionnaire, or equivalent evidence
- Right to audit: SecuryxAI reserves the right to conduct or commission a security assessment with 30 days’ notice
- Cooperation with SecuryxAI’s own compliance audits as required
Onboarding Process
New suppliers engaging with SecuryxAI must complete the following before processing any data:
- Complete the SecuryxAI Supplier Security Questionnaire
- Provide evidence of current SOC 2 Type II report or equivalent certification
- Sign a Data Processing Agreement (where applicable)
- Designate a security point of contact
- Receive written approval from SecuryxAI’s security team
Non-Compliance
Failure to meet these requirements may result in:
- Suspension of data access pending remediation
- Termination of the supplier relationship
- Notification to affected customers where a breach has occurred
Contact
Supplier security questions and questionnaire submissions: security@securyxai.com