Answers to security questionnaires
Your large customers send security questionnaires. Here are standard answers to adapt: only answer what is true and verifiable in your organization.
| Common question | Standard answer (to adapt) |
|---|---|
| Alignment with Law 25? | We have a designated RPRP, published policies, an incident register and carry out PIAs for new projects. |
| Where is data hosted? | [Region, e.g. Canada Central]. No transfer outside Québec without prior assessment. |
| Encryption? | TLS in transit; encryption at rest [AES-256]; keys managed in [KMS]. |
| Backups? | [Frequency], kept [duration], expiry documented. |
| Isolation between customers? | Database-level isolation and automated isolation tests. |
| Subprocessors? | List available at [URL]; [N] days' notice before any addition. |
| DPA? | We provide a standard DPA (limited use, incident notice, audit, deletion). |
| Incidents? | Internal alert within [N] h; notice to the customer without delay. |
| Certifications? | [SOC 2 Type II / ISO 27001: actual status]. |
| AI? | No training on your data without written consent. |
| Deletion at termination? | Final export then deletion, backups on their cycle, written confirmation. |
| GDPR? | Practices aligned with several GDPR principles; legal equivalence is not automatic. |
Every answer binds the company: have it validated by the RPRP and legal.