What's audited and retained?
All admin actions (login, role change, data export, configuration change) audit-logged with timestamp, actor, action, target. Logs retained 13 months. Per-tenant audit log exportable on Enterprise tier.
18 answers to the most common buyer security questions — hosting, sub-processors, encryption, auth, audit, vulnerability management, incident response, DR, compliance, DSR, residency, PHI. CAIQ / SIG / VSAQ-style structured responses. Cuts buyer-side discovery time from weeks to a single page read. Pairs with security controls, compliance glossary, RFP template.
What's audited and retained?
All admin actions (login, role change, data export, configuration change) audit-logged with timestamp, actor, action, target. Logs retained 13 months. Per-tenant audit log exportable on Enterprise tier.
What authentication mechanisms are supported?
Argon2id password hashing with per-tenant password policy. SAML SSO ships in the Enterprise tier (Okta, OneLogin, Azure AD, Google Workspace). SCIM provisioning roadmapped Q1 2027. 2FA / TOTP supported across all tiers.
Describe access controls.
Role-based access control (RBAC) per tenant. Repository pattern enforces ClientId partition key at compile time via static analyzer rule (SLATECH001). Cross-tenant data access is a structural impossibility, not a runtime check.
What are backup and DR capabilities?
Azure SQL daily backups with 35-day retention. Point-in-time recovery within last 24 hours. Vector-store snapshot to Azure Storage nightly. Multi-region failover across regions. RTO 4 hours, RPO 1 hour. DR runbook tested quarterly with simulated region failure.
Which compliance frameworks does SLAtech meet?
GDPR-compliant by default. HIPAA BAA-eligible on Enterprise tier (single-tenant). SOC 2 Type I report Q3 2026 target; Type II Q2 2027. ISO 27001 certification Q4 2026 target. PCI-DSS — SAQ-A applies (no cardholder data stored).
Which contract artefacts are available?
DPA, BAA, sub-processor list, SCC 2021/914 transfer-impact assessment, SoA gap-analysis mapping, vendor questionnaire (pre-filled). All available on request to security@slatech.ai. Enterprise tier MSA customisable.
Can data residency be pinned to specific region?
Custom Solutions and Enterprise tiers can pin hosting to a specific Azure region in your own jurisdiction (available on request). No data leaves the chosen region without explicit customer consent.
How are GDPR Articles 15-22 (DSR) honoured?
DSR portal in admin platform. Right of access (Article 15) — full data export in Markdown / JSON / PDF. Right to rectification (Article 16). Right to erasure (Article 17) — permanent deletion within 30 days. Right to portability (Article 20) — exports in machine-readable format. Right to object (Article 21) — opt-out controls per data category.
How is data-at-rest encrypted?
AES-256-GCM at rest on all storage layers (SQL Server tables, vector-store collections, Azure Blob document storage). Encryption keys managed by Azure Key Vault with annual rotation + rotation on personnel changes.
How is data-in-transit encrypted?
TLS 1.2+ enforced on every endpoint; HSTS preload set. SSL Labs A+ rating. Internal service-to-service communication also TLS-encrypted.
Where is customer data hosted?
SLAtech runs on a fully managed cloud with multi-region failover. Hosting in your own jurisdiction is available on request (Enterprise deployments) — single-tenant deployment pinned to a chosen Azure region.
What's the incident response procedure?
6-step procedure: detection (Sentry / synthetic) → triage (status page within 10 min) → mitigation (runbook applied) → resolution → public post-mortem within 5 business days → customer follow-up with service credit. 24-hour customer notification SLA for significant incidents (NIS2 alignment).
Is customer data used to train AI models?
No. Customer data is excluded from the model-training pipeline by contract and by technical isolation. Sub-processor agreements with our language-model and re-ranking providers explicitly exclude customer data from their training data.
How is sensitive personal data handled?
Detected structured identifiers (email, phone, payment card, Israeli national-ID, medical-record number) are replaced with tokens before any data leaves our servers to AI sub-processors; the originals stay encrypted at rest in our own vault and are never sent to those providers. This applies to opt-in document uploads (across all verticals) and to visitor chat messages. Free-text names, dates of birth and addresses are not auto-detected, and public website-crawled content is left as-is.
Which sub-processors process customer data?
A language-model provider (US, LLM inference), a re-ranking provider (Canada, optional), Sentry (US, errors), Cloudflare (global edge, WAF / CDN), SendGrid (US, email). All transfers governed by SCC 2021/914. Full list kept current within 14 days of change.
What happens to customer data on contract termination?
30-day notice for termination of convenience. On termination, customer data exportable for 90 days (Markdown / JSON knowledge content + JSONL conversation history). After 90 days, all customer data is permanently deleted from production and backups within 35 additional days.
Can customers veto sub-processor changes?
Customers receive 30-day notice before adding a new sub-processor. Custom Solutions tier customers can veto a sub-processor (with migration to a non-veto path or contract exit). Multi-tenant tiers (Starter / Pro / Enterprise): notice but no veto.
Describe the vulnerability management program.
Dependabot automated dependency updates on production branch. GitHub CodeQL static analysis on every PR. Annual external penetration test (next Q4 2026). Coordinated vulnerability disclosure policy.
For SIG, CAIQ, VSAQ or custom enterprise questionnaires — turnaround 2-3 business days.
Four self-serve tools for evaluating SLAtech (or any AI chatbot vendor) without a sales call: