Our security, compliance, and policy documentation, including audit reports.
Anonymous Whistleblower Channel
Provide evidence that the organization has an anonymized channel for employees to report deviations from internal controls and trust services criteria. Acceptable evidence includes a screenshot or link showing where and how employees can anonymously submit security or privacy concerns, such as through a form or third-party tool.
Apr 2026
Application User Authentication Page
Provide evidence that the organization requires unique a user ID and password in their authentication page.
No date
Architecture Diagram
Provide an architecture diagram that outlines the organization’s system design and key infrastructure components. It should clearly show core services, integrations, and a segmented network architecture. The diagram must also illustrate how data flows through the system. This includes where it is collected, stored, processed, transmitted, and accessed. Be sure to include internal systems, external services, user interfaces, databases, and any third-party or cloud integrations.
Mar 2026
Authorities and Special Interest Group List
Provide evidence that the organization keeps a list of contacts with authorities and special-interest groups, along with a brief explanation of each contact's role and relevance to security and privacy.
Apr 2026
Board of Directors CVs
Provide CVs or LinkedIn profile links for all members of the board of directors.
Mar 2026
Board of Directors Evaluation Criteria
Provide evidence that the Board of Directors undergoes a structured evaluation to assess its performance, effectiveness, and dynamics. Evidence may include evaluation criteria, questionnaires, meeting minutes documenting the evaluation process, or reports summarizing outcomes and follow-ups.
Mar 2026
Bring Your Own Device
MDM is not enforced until Indigetech supplies company issued devices