EvidenceTrail procurement answer pack Schema version: 2026-07-05.day16 Scope: controlled_pilot_procurement_answers Procurement page: /procurement-pack JSON source: /procurement-pack/answers.json Limitations - This is not a completed buyer questionnaire. - This is not a signed DPA, completed DPIA, security certification, or pen test. - Buyer legal, DPO, security, and operations owners must approve production use. Current answers 1. Access control and tenant isolation Current answer: Prototype access uses role-bound operator keys, organisation allowlisting, and single-use proof links. It does not evidence production SSO, MFA, SCIM, password policy, or persistent user directory. Evidence today: Admin tenant-isolation report, identity-provider tenant-mapping readiness, role-capability evidence, and proof-link replay protections. Owner to confirm: security owner Required before production: Production SSO, MFA, SCIM/deprovisioning, session policy, and formal audit. 2. Data processing and Article 28 Current answer: Processor posture is documented for pilot review, but legal terms are unsigned. Evidence today: DPA/DPIA technical annex and data-processing/cookies posture page. Owner to confirm: customer legal owner Required before production: Customer-approved Article 28 terms, DPIA support pack, and privacy notice. 3. Cyber Essentials and cloud security Current answer: EvidenceTrail is not Cyber Essentials certified. Evidence today: Security baseline and NCSC Cloud Security Principles launch gate. Owner to confirm: security owner Required before production: Cyber Essentials or buyer-approved equivalent and cloud control mapping. 4. Incident response and breach support Current answer: Draft intake and incident-response workflows exist; no live monitored contact. Evidence today: Security contact intake draft and incident-response draft. Owner to confirm: operations owner Required before production: Live security contact, tested escalation, controller notification support, tabletop. 5. Backup, restore, and business continuity Current answer: SQLite prototype restore probe exists; no approved production DR posture. Evidence today: Backup/restore draft and executable prototype restore probe. Owner to confirm: operations owner Required before production: Customer-approved RPO/RTO, encrypted backups, restore evidence, DR owner. 6. Vulnerability and dependency management Current answer: Dependency-audit scaffold exists; no production CI security gate or pen test. Evidence today: Dependency checks, procurement dependency template, and security baseline. Owner to confirm: security owner Required before production: CI scanning, vulnerability-management owner, disclosure programme, pen test. Buyer-use boundary This text export supports controlled pilot procurement review. It is not production approval, a signed DPA, certification evidence, or legal advice.