Send this to procurement.
Security · the questions procurement asks
The questions security asks, answered before the call. The full packet is one email away.
Only the named sources.
The workflow reads only the sources named in the statement of work. Nothing else is connected. Nothing is retained beyond the record you approve.
Least permission, revocable by you.
Scoped credentials per source, revocable by you in one step, never shared across clients.
Named humans hold the decisions.
Release, spend and exception decisions sit with people you name. The system cannot approve its own output.
Tests written on day 2.
Acceptance tests are written down with you on day 2. Outputs run against agreed examples and source data before anything is released.
Every run, on your record.
Every run, exception and approval is logged. The log belongs to you and leaves with you.
A defined path, not a drawer.
After day 7 there is a defined response path. Incidents and their resolution appear on the monthly operating record.
Named per engagement.
Model providers: OpenAI, Anthropic or Google, chosen per step and named in the statement of work. No hidden third parties.
Yours, and it leaves with you.
The workflow, its controls and its logs are yours. Prefer to run it fully in-house? We hand over clean and stay one call away.
Everything on this page in the form your security team files, plus your questionnaire completed.
- Data-flow diagram
- Access model
- Incident path
- Sub-processor list
- Written policies: access control, incident response, vendor management
- Your questionnaire, completed (SIG Lite or CAIQ style)
Certifications: none claimed. No SOC 2 report yet, and we will not imply one. For mid-market engagements a completed questionnaire and written policies are what procurement files; when a deal needs the audit, we will say so and get it.
20 minutes. A straight answer.
Bring your security questionnaire. We answer it line by line on the call—or send the packet first and talk after.
Security first? Ask for the packet: data boundary, access, approvals, logs.
No email app set up? Write hello@agentsautonomous.com