Clear answers
Security questions, answered.
Does a signed record prove compliance?
No. A signature supports authenticity and integrity of the covered data. Compliance depends on the applicable obligations, the underlying facts, and the actions taken. Review the record with the appropriate legal and assurance specialists.
How are authentication and sessions handled?
IR-OS uses Supabase authentication with application session handling. Confirm the identity configuration, session requirements, offboarding process, and any enterprise identity integration during your security review.
Which standards inform the workflows?
Existing plan options include NIST, ISO/IEC 27035, CISA, SANS PICERL, and the IR-OS Expert template. Framework selection supports planning; it does not confer certification. Review the version and applicability of your selected plan.
NIST SP 800-61 Rev. 3 supersedes Rev. 2. Existing legacy templates should be reviewed against current guidance.
Are regulatory clocks legal filing deadlines?
Planning estimates require confirmation of applicability, the triggering event, and the correct calendar. Record the reviewed obligation, owner, and evidence. For example, SEC Item 1.05 generally uses four business days after a materiality determination, not a fixed 96 hours after discovery.
Read the SEC disclosure guidance.
Where can I review subprocessors and compliance requirements?
Start with the privacy policy and subprocessor information. Request current documentation for your deployment. Confirm required certifications, residency, a BAA, and contractual commitments explicitly; a roadmap item is not a delivered control.
What should we confirm about incident communications?
Agree on your security contacts, escalation route, contractual notification requirements, and follow-up reporting during procurement. Notification obligations depend on the incident and applicable law; one universal reporting deadline does not apply to every customer.