Security questionnaire

Pre-filled procurement security responses

18 answers to the most common buyer security questions — hosting, sub-processors, encryption, auth, audit, vulnerability management, incident response, DR, compliance, DSR, residency, PHI. CAIQ / SIG / VSAQ-style structured responses. Cuts buyer-side discovery time from weeks to a single page read. Pairs with security controls, compliance glossary, RFP template.

Audit logging

What's audited and retained?

All admin actions (login, role change, data export, configuration change) audit-logged with timestamp, actor, action, target. Logs retained 13 months. Per-tenant audit log exportable on Enterprise tier.

Evidence: /en/security/

Authentication

What authentication mechanisms are supported?

Argon2id password hashing with per-tenant password policy. SAML SSO ships in the Enterprise tier (Okta, OneLogin, Azure AD, Google Workspace). SCIM provisioning roadmapped Q1 2027. 2FA / TOTP supported across all tiers.

Evidence: /en/security/

Authorization

Describe access controls.

Role-based access control (RBAC) per tenant. Repository pattern enforces ClientId partition key at compile time via static analyzer rule (SLATECH001). Cross-tenant data access is a structural impossibility, not a runtime check.

Evidence: /en/architecture/#multi-tenant-data-isolation

Backup & recovery

What are backup and DR capabilities?

Azure SQL daily backups with 35-day retention. Point-in-time recovery within last 24 hours. Vector-store snapshot to Azure Storage nightly. Multi-region failover across regions. RTO 4 hours, RPO 1 hour. DR runbook tested quarterly with simulated region failure.

Evidence: /en/architecture/#disaster-recovery-posture

Compliance certifications

Which compliance frameworks does SLAtech meet?

GDPR-compliant by default. HIPAA BAA-eligible on Enterprise tier (single-tenant). SOC 2 Type I report Q3 2026 target; Type II Q2 2027. ISO 27001 certification Q4 2026 target. PCI-DSS — SAQ-A applies (no cardholder data stored).

Evidence: /en/compliance/

Contract artefacts

Which contract artefacts are available?

DPA, BAA, sub-processor list, SCC 2021/914 transfer-impact assessment, SoA gap-analysis mapping, vendor questionnaire (pre-filled). All available on request to security@slatech.ai. Enterprise tier MSA customisable.

Evidence: /en/rfp-template/

Data residency

Can data residency be pinned to specific region?

Custom Solutions and Enterprise tiers can pin hosting to a specific Azure region in your own jurisdiction (available on request). No data leaves the chosen region without explicit customer consent.

Evidence: /en/architecture/

Data subject rights

How are GDPR Articles 15-22 (DSR) honoured?

DSR portal in admin platform. Right of access (Article 15) — full data export in Markdown / JSON / PDF. Right to rectification (Article 16). Right to erasure (Article 17) — permanent deletion within 30 days. Right to portability (Article 20) — exports in machine-readable format. Right to object (Article 21) — opt-out controls per data category.

Evidence: /en/compliance/

Encryption at rest

How is data-at-rest encrypted?

AES-256-GCM at rest on all storage layers (SQL Server tables, vector-store collections, Azure Blob document storage). Encryption keys managed by Azure Key Vault with annual rotation + rotation on personnel changes.

Evidence: /en/security/

Encryption in transit

How is data-in-transit encrypted?

TLS 1.2+ enforced on every endpoint; HSTS preload set. SSL Labs A+ rating. Internal service-to-service communication also TLS-encrypted.

Evidence: /en/security/

Hosting

Where is customer data hosted?

SLAtech runs on a fully managed cloud with multi-region failover. Hosting in your own jurisdiction is available on request (Enterprise deployments) — single-tenant deployment pinned to a chosen Azure region.

Evidence: /en/architecture/#deployment-topology

Incident response

What's the incident response procedure?

6-step procedure: detection (Sentry / synthetic) → triage (status page within 10 min) → mitigation (runbook applied) → resolution → public post-mortem within 5 business days → customer follow-up with service credit. 24-hour customer notification SLA for significant incidents (NIS2 alignment).

Evidence: /en/uptime/

Model training

Is customer data used to train AI models?

No. Customer data is excluded from the model-training pipeline by contract and by technical isolation. Sub-processor agreements with our language-model and re-ranking providers explicitly exclude customer data from their training data.

Evidence: /en/ethics/

PHI / PII handling

How is sensitive personal data handled?

Detected structured identifiers (email, phone, payment card, Israeli national-ID, medical-record number) are replaced with tokens before any data leaves our servers to AI sub-processors; the originals stay encrypted at rest in our own vault and are never sent to those providers. This applies to opt-in document uploads (across all verticals) and to visitor chat messages. Free-text names, dates of birth and addresses are not auto-detected, and public website-crawled content is left as-is.

Evidence: /en/compliance/#phi-protected-health-information

Sub-processors

Which sub-processors process customer data?

A language-model provider (US, LLM inference), a re-ranking provider (Canada, optional), Sentry (US, errors), Cloudflare (global edge, WAF / CDN), SendGrid (US, email). All transfers governed by SCC 2021/914. Full list kept current within 14 days of change.

Evidence: /en/sub-processors/

Termination & data return

What happens to customer data on contract termination?

30-day notice for termination of convenience. On termination, customer data exportable for 90 days (Markdown / JSON knowledge content + JSONL conversation history). After 90 days, all customer data is permanently deleted from production and backups within 35 additional days.

Evidence: /en/rfp-template/

Vendor selection of sub-processors

Can customers veto sub-processor changes?

Customers receive 30-day notice before adding a new sub-processor. Custom Solutions tier customers can veto a sub-processor (with migration to a non-veto path or contract exit). Multi-tenant tiers (Starter / Pro / Enterprise): notice but no veto.

Evidence: /en/sub-processors/

Vulnerability management

Describe the vulnerability management program.

Dependabot automated dependency updates on production branch. GitHub CodeQL static analysis on every PR. Annual external penetration test (next Q4 2026). Coordinated vulnerability disclosure policy.

Evidence: /en/security/

Need a custom security questionnaire response?

For SIG, CAIQ, VSAQ or custom enterprise questionnaires — turnaround 2-3 business days.

Buyer evaluation tools

Four self-serve tools for evaluating SLAtech (or any AI chatbot vendor) without a sales call:

Eval scoreboard 200-question methodology TCO calculator Annual savings + payback Vendor compare-tool Filter 16 vendors Vendor checklist 30 procurement questions