EvidenceTrail Trust file

EvidenceTrail security questionnaire

Procurement-readable questionnaire readiness for UK social-landlord pilot review.

Current source artifact: docs/security-questionnaire-readiness.md.

Phase 2 update

Phase 2 announced for Oct 2026: see what changes.

Security questionnaire readiness matrix

This is not a completed buyer questionnaire, not a signed DPA, not Cyber Essentials certified, not a penetration-test report, and not production security evidence. It is a conservative readiness matrix for pilot procurement review.

Buyer decision summary

Suitable for controlled pilot security review, not production security approval. Each row names the evidence available today, the owner to confirm it, and the blocker that must close before production. Buyer policy should decide whether the current evidence is enough for a bounded design-partner or pilot review.

Usable for pilot review

Role-bound keys, organisation allowlisting, proof-link protections, and prototype audit evidence can support bounded buyer review.

Not production-ready evidence

Still missing signed DPA, completed DPIA, Cyber Essentials evidence, pen test, SSO/MFA/SCIM evidence, and live monitored security contact.

Owner decisions still open

Security, customer legal, and operations owners must confirm the production controls, policy acceptance, and launch blockers.

Current answers and missing production evidence
Question area Current answer Evidence today Owner to confirm Required before production
Access control and tenant isolationPrototype access uses role-bound operator keys, organisation allowlisting, and single-use proof links. It does not evidence production SSO, MFA, SCIM, password policy, or persistent user directory.Admin tenant-isolation report, identity-provider tenant-mapping readiness, role-capability evidence, and proof-link replay protections.security ownerProduction SSO, MFA, SCIM/deprovisioning, session policy, and formal audit.
Data processing and Article 28Processor posture is documented for pilot review, but legal terms are unsigned.DPA/DPIA technical annex and data-processing/cookies posture page.customer legal ownerCustomer-approved Article 28 terms, DPIA support pack, and privacy notice.
Cyber Essentials and cloud securityEvidenceTrail is not Cyber Essentials certified.Security baseline and NCSC Cloud Security Principles launch gate.security ownerCyber Essentials or buyer-approved equivalent and cloud control mapping.
Incident response and breach supportDraft intake and incident-response workflows exist; no live monitored contact.Security contact intake draft and incident-response draft.operations ownerLive security contact, tested escalation, controller notification support, tabletop.
Backup, restore, and business continuitySQLite prototype restore probe exists; no approved production DR posture.Backup/restore draft and executable prototype restore probe.operations ownerCustomer-approved RPO/RTO, encrypted backups, restore evidence, DR owner.
Vulnerability and dependency managementDependency-audit scaffold exists; no production CI security gate or pen test.Dependency checks, procurement dependency template, and security baseline.security ownerCI scanning, vulnerability-management owner, disclosure programme, pen test.