Answers to security questionnaires

Your large customers send security questionnaires. Here are standard answers to adapt: only answer what is true and verifiable in your organization.

Common question Standard answer (to adapt)
Alignment with Law 25? We have a designated RPRP, published policies, an incident register and carry out PIAs for new projects.
Where is data hosted? [Region, e.g. Canada Central]. No transfer outside Québec without prior assessment.
Encryption? TLS in transit; encryption at rest [AES-256]; keys managed in [KMS].
Backups? [Frequency], kept [duration], expiry documented.
Isolation between customers? Database-level isolation and automated isolation tests.
Subprocessors? List available at [URL]; [N] days' notice before any addition.
DPA? We provide a standard DPA (limited use, incident notice, audit, deletion).
Incidents? Internal alert within [N] h; notice to the customer without delay.
Certifications? [SOC 2 Type II / ISO 27001: actual status].
AI? No training on your data without written consent.
Deletion at termination? Final export then deletion, backups on their cycle, written confirmation.
GDPR? Practices aligned with several GDPR principles; legal equivalence is not automatic.

Every answer binds the company: have it validated by the RPRP and legal.