
Deployment and security planning questions
Use this discussion guide to agree hosting, access, data handling, integrations and operating responsibilities for a proposed deployment.
How the platforms are deployed, what the security model looks like, and what an assessment team usually wants to know before a pilot is approved.
What the document covers.
Deployment options, including hosting by us and hosting inside your own environment, and what changes between them in terms of responsibility. Identity and access: single sign-on, role-based access control, and how local accounts are handled where single sign-on is not available. Data residency and separation between tenants. Audit coverage over create, update and delete. Logging and retention. Backup and recovery objectives. And the integration surface, with the authentication model for each.
Who asks for this.
Information security teams, IT assurance, and procurement teams working through a supplier questionnaire. It is written to answer most of a standard questionnaire directly, so that the remaining questions are the ones that genuinely need a conversation.
On what it does not claim.
Where a control is planned rather than in place, the document says so. A security overview that reads as though everything is already certified is not useful to an assessor and does not survive the first follow-up question.
What would a better working day look like?
Bring us the process you want to improve. We’ll explore the product, technology and delivery work it needs.
