| AI & Agentic Security | Workato Public Trust Center | RFPIO / Responsive (Profile Center) | documented | - | - |
| Compliance & Governance | Workato Public Trust Center | RFPIO / Responsive (Profile Center) | documented | - | - |
| Data Protection | Workato Public Trust Center | RFPIO / Responsive (Profile Center) | documented | - | - |
| "Un-owned" physical storage is prohibited | Epsilon3 | Vanta Trust Center | documented | - | - |
| [CCF] Data Encryption at Rest | Blockdaemon | Vanta Trust Center | documented | - | - |
| [CCF] Data retention procedures established | Blockdaemon | Vanta Trust Center | documented | - | - |
| + List of Infosec Policies | Infoblox | SafeBase | documented | - | - |
| ✅ Customer personally identifiable information | sentillia.com | Vanta Trust Center | documented | - | - |
| ✅ Employee personally identifiable information | sentillia.com | Vanta Trust Center | documented | - | - |
| 09.s Transmission Protection | PatientIQ | Vanta Trust Center | documented | - | - |
| 1 - Board meetings conducted | Snappy | Vanta Trust Center | documented | - | - |
| 1 - Gong Trust Brochure - Security, Privacy, AI Whitepaper | Gong | SafeBase | documented | - | - |
| 1 Risk Standard Terms & Conditions (STC) Data Processing | Accesso Technology Group | SafeBase | documented | - | - |
| 1. Privacy Notice | Everbridge | SafeBase | documented | - | - |
| 1.1 Processes and mechanisms for installing and maintaining network security controls are defined and understood. | Staq.io | Vanta Trust Center | documented | - | - |
| 1.1.1 | Xactus | Vanta Trust Center | documented | - | - |
| 1.1.1 Code of Conduct / Handbook acknowledged by employees and enforced | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.1.2 | Xactus | Vanta Trust Center | documented | - | - |
| 1.1.3 Confidentiality Agreement acknowledged by employees | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.1.7 Performance evaluations conducted | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.2 Network security controls (NSCs) are configured and maintained. | Staq.io | Vanta Trust Center | documented | - | - |
| 1.2.1 | Xactus | Vanta Trust Center | documented | - | - |
| 1.2.1a Executive management charter documented | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.2.1b Executive management oversight responsibilities are defined and documented and acknowledged on an annual basis. | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.2.2 | Xactus | Vanta Trust Center | documented | - | - |
| 1.2.2 Executive Management Expertise Verified Annually | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.2.3 | Xactus | Vanta Trust Center | documented | - | - |
| 1.2.4 | Xactus | Vanta Trust Center | documented | - | - |
| 1.2.5 | Xactus | Vanta Trust Center | documented | - | - |
| 1.2.6 | Xactus | Vanta Trust Center | documented | - | - |
| 1.2.7 | Xactus | Vanta Trust Center | documented | - | - |
| 1.2.8 | Xactus | Vanta Trust Center | documented | - | - |
| 1.3 Network access to and from the cardholder data environment is restricted. | Staq.io | Vanta Trust Center | documented | - | - |
| 1.3.1 | Xactus | Vanta Trust Center | documented | - | - |
| 1.3.1 Control self-assessments conducted | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.3.2 | Xactus | Vanta Trust Center | documented | - | - |
| 1.3.2 Roles and responsibilities specified | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.3.3 | Xactus | Vanta Trust Center | documented | - | - |
| 1.3.3 Organization structure documented | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.4.1 | Xactus | Vanta Trust Center | documented | - | - |
| 1.4.1 Security awareness training implemented | Broker Buddha Technologies Inc. | Vanta Trust Center | documented | - | - |
| 1.4.2 | Xactus | Vanta Trust Center | documented | - | - |
| 1.4.3 | Xactus | Vanta Trust Center | documented | - | - |
| 1.4.4 | Xactus | Vanta Trust Center | documented | - | - |
| 1.4.5 | Xactus | Vanta Trust Center | documented | - | - |
| 1.5 Risks to the CDE from computing devices that are able to connect to both untrusted networks and the CDE are mitigated. | Staq.io | Vanta Trust Center | documented | - | - |
| 1.5.1 | Xactus | Vanta Trust Center | documented | - | - |
| 10.1 Processes and mechanisms for logging and monitoring all access to system components and cardholder data are defined and understood. | Staq.io | Vanta Trust Center | documented | - | - |
| 10.1.1 | Xactus | Vanta Trust Center | documented | - | - |
| 10.1.2 | Xactus | Vanta Trust Center | documented | - | - |