Acme Cloud Services
Acme Identity Platform (SaaS)
Confidential — for the recipient organisation's internal decision use only
Supports Approval with Conditions
This recommendation is evidence-based decision support. The final procurement decision remains with the recipient organisation.
Evidence partially supports the reviewed requirements. EU data-residency confirmation and a reconciled breach-notification SLA are required before the assessment can be closed; all other reviewed requirements are supported by independent evidence.
Acme Cloud Services provides strong evidence for the majority of reviewed security and privacy requirements. Independently verified SOC 2 Type II and ISO 27001 certifications support core control areas. Two requirements lack supporting evidence and one conflict between documents requires vendor clarification before final approval.
Supported — requirements the vendor's evidence clearly satisfies. Needs attention — partial coverage, unresolved conflicts or open follow-up questions. Missing — requirements with no supporting evidence provided.
Ready = evidence is sufficient to decide. Partial = some material gaps remain. Not Ready = key evidence is missing or conflicting.
- Breach notification SLA
- Data residency / processing region commitments for EU customers
- Penetration test executive summary from the last 12 months
- Encryption controls
- Access control governance
- Business continuity testing
- 01Request written confirmation of EU data residency from vendor before contract sign-off.High priority
- 02Ask vendor to reconcile breach-notification SLA between DPA and Security Policy.Medium priority
- 03Obtain the latest penetration test executive summary and remediation status.Medium priority
- 04Schedule annual reassessment aligned with SOC 2 report refresh cycle.Low priority
Requirements assessment
Each reviewed requirement, mapped to the evidence the vendor provided.
Requirements mapping
8 requirements- REQ-02Evidence foundCritical priorityAll customer data must be encrypted at rest and in transit.
AES-256 at rest, TLS 1.2+ in transit, documented in Security Whitepaper §3.2.
- Follow-upREQ-04No evidenceCritical priorityCustomer data processed within EU/EEA boundaries.
No documentation found specifying processing regions or data residency commitments.
- REQ-01Evidence foundHigh priorityVendor must hold a current independent security certification (SOC 2 / ISO 27001).
SOC 2 Type II (BDO, 2025) and ISO 27001:2022 certificate provided.
- REQ-03Evidence foundHigh priorityMulti-factor authentication enforced for all administrative access.
Confirmed in SOC 2 control CC6.1 and Access Control Policy §4.
- Follow-upREQ-05Partial evidenceHigh prioritySecurity incidents notified to customers within agreed SLA.
DPA states 24 hours; Security Policy states 72 hours. Conflict pending clarification.
- Follow-upREQ-06Manual reviewMedium priorityAnnual penetration testing performed by an independent third party.
Reference to annual pentests in Security Whitepaper, but no recent report provided.
- REQ-07Evidence foundMedium priorityDocumented Business Continuity and Disaster Recovery plan with annual testing.
BCP / DRP document provided with 2024 test results.
- REQ-08Evidence foundMedium prioritySub-processor list maintained and customers notified of changes.
Sub-processor list provided; change notification process in DPA §6.
Detailed findings1 high · 1 medium · 1 low
- Low severitySOC 2 Type II report covers all in-scope trust criteria
Independent auditor opinion (BDO, 2025) confirms operating effectiveness of controls for Security, Availability and Confidentiality over a 12-month review period with no exceptions.
- High severityData residency commitments not documented
Provided contracts and policies do not specify guaranteed processing regions for EU customer data. Required for GDPR data transfer assessment.
- Medium severityIncident notification SLA inconsistency
The DPA commits to 24-hour breach notification while the Security Policy references 72 hours. Vendor clarification required.
Conflicting information1
- Breach notification SLA
The Data Processing Addendum commits to 24-hour breach notification, while the Security Policy references 72 hours. The shorter commitment in the DPA should be confirmed as authoritative.
Evidence
The documents supplied, the requirements they support, and the gaps that remain.
Decision readiness Additional Evidence Required
Supporting evidence3
| Topic | Evidence strength | Supporting documents |
|---|---|---|
Encryption controls Encryption at rest (AES-256) and in transit (TLS 1.2+) is confirmed independently in the SOC 2 Type II report and the Security Whitepaper. | Strong | |
Access control governance Role-based access control with MFA for administrators is consistent across the Access Control Policy and SOC 2 control CC6.1. | Strong | |
Business continuity testing Annual BCP/DRP testing is documented both in the BCP document and the SOC 2 report (control A1.2). | Strong |
Requirements without supporting evidence2
- Data residency / processing region commitments for EU customers
- Penetration test executive summary from the last 12 months
Recommended additional evidence3
- Data Processing Addendum with explicit processing regions
- Most recent penetration test executive summary
- Business continuity plan test results from the last 12 months
Follow-up questions for the vendor5
- 01High priorityCan you confirm in writing that EU customer data is processed exclusively within the EU/EEA, and provide the relevant DPA addendum?
Required for our GDPR transfer assessment.
- 02High priorityWhich SLA is authoritative for breach notification — 24 hours (DPA) or 72 hours (Security Policy)?
- 03Medium priorityPlease share the executive summary of your most recent independent penetration test and the remediation status of any findings.
- 04Low priorityDo you maintain a customer-facing trust portal where sub-processor changes are communicated proactively?
- 05Medium priorityPlease confirm the retention period for customer data after contract termination.
Methodology & reference
How this report was produced, and supplementary detail for review teams.
Methodology
Governly maps customer-supplied requirements to vendor evidence across Information Security, Data Protection & Privacy, Access Control & Identity, Business Continuity & Resilience, Vendor Governance, and Documentation Completeness. Each requirement is independently evaluated; the report highlights what is supported, what is missing, and what requires manual verification.
Numerical scoring (supplementary)
- Information Security86 / 100
- Data Protection & Privacy68 / 100
Lowered by missing residency evidence.
- Access Control & Identity84 / 100
- Business Continuity & Resilience74 / 100
- Vendor Governance80 / 100
- Documentation Completeness76 / 100
- Independent SOC 2 Type II and ISO 27001 certifications provided
- Two requirements without supporting evidence
- One inter-document conflict identified
Numerical scores are supplementary. The primary assessment is the requirement-by-requirement evidence review above.