Cloud security self-assessment
We use the Cloud Security Alliance CAIQ-Lite v4.1.0 to describe our cloud security controls and shared responsibilities.
Last updated August 2026
This self-assessment covers GreenTriangle AG and the unified GT SaaS platform. It uses CAIQ-Lite v4.1.0, based on the Cloud Security Alliance Cloud Controls Matrix v4.1. The current CAIQ-Lite contains 138 questions across 17 domains. Answers describe controls operating on 27 August 2026 and the shared responsibilities of GreenTriangle, its service providers and customers.
Response summary: 137 Yes; 0 No; 1 N/A.
The August 2026 assurance cycle included authenticated web and API testing and a source and configuration review through an external security platform provider. Neither produced a High or Critical finding. Medium and lower observations remain subject to the normal findings, correction and retest process. This CAIQ is a supplier self-assessment.
| Domain | Control | ID | Question | Answer | Ownership | Implementation |
|---|---|---|---|---|---|---|
| Audit & Assurance | Independent Assessments | A&A-02.1 | Are independent audit and assurance assessments conducted according to relevant standards at least annually? | Yes | Shared CSP and third party | Independent annual assurance covers the EU hosting and cloud providers used by the service. |
| Audit & Assurance | Risk Based Planning Assessment | A&A-03.1 | Are independent audit and assurance assessments performed according to risk-based plans and policies, and in response to significant changes or emerging risks? | Yes | Shared CSP and third party | Security reviews follow the risk register and are repeated after material changes. The 2026 assurance cycle included authenticated web and API testing, source and configuration review through an external security platform provider, and infrastructure-provider assurance checks. |
| Audit & Assurance | Requirements Compliance | A&A-04.1 | Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit? | Yes | CSP-owned | Applicable legal, privacy, contractual and security obligations are reviewed through the ISMS, customer due diligence, DPAs and contract approval. |
| Audit & Assurance | Remediation | A&A-06.1 | Is a risk-based corrective action plan to remediate audit findings established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Findings are recorded with severity, owner, target date, correction and retest evidence. Critical findings are contained within four hours and corrected within seven days; High findings are corrected within 30 days. |
| Audit & Assurance | Remediation | A&A-06.2 | Is the remediation status of audit findings regularly reviewed and reported to relevant stakeholders? | Yes | CSP-owned | Findings are recorded with severity, owner, target date, correction and retest evidence. Critical findings are contained within four hours and corrected within seven days; High findings are corrected within 30 days. |
| Application & Interface Security | Application Security Baseline Requirements | AIS-02.1 | Are baseline requirements to secure applications established, documented, and maintained? | Yes | CSP-owned | Application baselines require reviewed changes, secure authentication and authorization, tenant isolation, input validation, protected secrets, automated tests and staging validation. |
| Application & Interface Security | Secure Application Development Lifecycle | AIS-04.1 | Is a secure SDLC process defined and implemented for application requirements analysis, planning, design, development, testing, deployment, and operation per organizationally designed security requirements? | Yes | CSP-owned | The SDLC covers requirements, design, peer review, automated testing, database validation, security checks, staged release, production monitoring and rollback. |
| Application & Interface Security | Secure Application Deployment | AIS-06.1 | Are strategies and capabilities established and implemented to deploy application code in a secure, standardized, and compliant manner? | Yes | CSP-owned | Version-controlled pipelines build, test and deploy approved releases to staging and production. Production promotion is controlled and an automated rollback path retains the last known-good release. |
| Application & Interface Security | Secure Application Deployment | AIS-06.2 | Is the deployment and integration of application code automated where possible? | Yes | CSP-owned | Version-controlled pipelines build, test and deploy approved releases to staging and production. Production promotion is controlled and an automated rollback path retains the last known-good release. |
| Application & Interface Security | Application Vulnerability Remediation | AIS-07.1 | Are application security vulnerabilities remediated following defined processes? | Yes | CSP-owned | Application and dependency findings are triaged by risk, corrected through the normal reviewed release process and retested. Automated checks support detection and safe dependency updates. |
| Application & Interface Security | Application Vulnerability Remediation | AIS-07.2 | Is the remediation of application security vulnerabilities automated when possible? | Yes | CSP-owned | Application and dependency findings are triaged by risk, corrected through the normal reviewed release process and retested. Automated checks support detection and safe dependency updates. |
| Application & Interface Security | API Security | AIS-08.1 | Are processes, procedures, and technical measures defined and implemented to secure APIs? | Yes | CSP-owned | External APIs use OAuth 2.0/OIDC bearer tokens, authorization scopes, tenant-aware database controls, validation, TLS, audit records and rate controls. Versioned customer API documentation is maintained. |
| Application & Interface Security | API Security | AIS-08.2 | Are reviews and updates for any improvements conducted at least annually, or upon significant changes? | Yes | CSP-owned | External APIs use OAuth 2.0/OIDC bearer tokens, authorization scopes, tenant-aware database controls, validation, TLS, audit records and rate controls. Versioned customer API documentation is maintained. |
| Business Continuity Management and Operational Resilience | Business Continuity Management Policy and Procedures | BCR-01.1 | Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | A version-controlled business continuity plan defines critical services, recovery responsibilities, communications, RTO/RPO targets and periodic review after material changes. |
| Business Continuity Management and Operational Resilience | Business Continuity Management Policy and Procedures | BCR-01.2 | Are the policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | A version-controlled business continuity plan defines critical services, recovery responsibilities, communications, RTO/RPO targets and periodic review after material changes. |
| Business Continuity Management and Operational Resilience | Risk Assessment and Impact Analysis | BCR-02.1 | Are criteria for developing business continuity and operational resiliency strategies and capabilities established based on business disruption and risk impacts? | Yes | CSP-owned | The continuity analysis ranks critical services and considers personnel, hosting, database, storage, authentication and remote-sensing dependencies. It is reviewed with the risk register and material architecture changes. |
| Business Continuity Management and Operational Resilience | Risk Assessment and Impact Analysis | BCR-02.2 | Are the risk assessment and impact analysis reviewed and updated at least annually or upon significant changes? | Yes | CSP-owned | The continuity analysis ranks critical services and considers personnel, hosting, database, storage, authentication and remote-sensing dependencies. It is reviewed with the risk register and material architecture changes. |
| Business Continuity Management and Operational Resilience | Business Continuity Strategy | BCR-03.1 | Are strategies being established to reduce the impact of business disruptions, and are resiliency and recovery from business disruptions being improved? | Yes | Shared CSP and third party | Resilience uses geographically distributed personnel, a secondary application host, PostgreSQL primary/standby, transaction-log archiving and independent EU backup repositories. |
| Business Continuity Management and Operational Resilience | Backup | BCR-08.1 | Are backups performed periodically? | Yes | Shared CSP and third party | PostgreSQL backups, continuous transaction-log archiving and object-storage backups are retained in separate EU locations. Backup age and archiving are monitored, and restoration procedures are tested. |
| Business Continuity Management and Operational Resilience | Backup | BCR-08.2 | Is the confidentiality, integrity, and availability of the backup ensured? | Yes | Shared CSP and third party | PostgreSQL backups, continuous transaction-log archiving and object-storage backups are retained in separate EU locations. Backup age and archiving are monitored, and restoration procedures are tested. |
| Business Continuity Management and Operational Resilience | Backup | BCR-08.3 | Can backups be restored appropriately for resiliency? | Yes | Shared CSP and third party | PostgreSQL backups, continuous transaction-log archiving and object-storage backups are retained in separate EU locations. Backup age and archiving are monitored, and restoration procedures are tested. |
| Business Continuity Management and Operational Resilience | Disaster Response Plan | BCR-09.1 | Is a disaster response plan established, documented, approved, applied, evaluated, and maintained to ensure recovery from natural and man-made disasters? | Yes | Shared CSP and third party | The continuity plan covers natural, technical, supplier and human disruption. It is reviewed at least annually and after significant service or risk changes. |
| Business Continuity Management and Operational Resilience | Disaster Response Plan | BCR-09.2 | Is the disaster response plan updated at least annually, and when significant changes occur? | Yes | Shared CSP and third party | The continuity plan covers natural, technical, supplier and human disruption. It is reviewed at least annually and after significant service or risk changes. |
| Change Control and Configuration Management | Change Management Policy and Procedures | CCC-01.1 | Are policies and procedures for managing the risks associated with applying changes to assets owned, controlled, or used by the organization established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Change risk is controlled through version control, peer review, automated tests, staged validation, approval, traceable deployment and rollback. The process is reviewed after major delivery changes and under the ISMS cycle. |
| Change Control and Configuration Management | Change Management Policy and Procedures | CCC-01.2 | Are the policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Change risk is controlled through version control, peer review, automated tests, staged validation, approval, traceable deployment and rollback. The process is reviewed after major delivery changes and under the ISMS cycle. |
| Change Control and Configuration Management | Quality Testing | CCC-02.1 | Is a defined quality change control, approval and testing process, incorporating baselines, testing, and release standards, established, maintained and implemented? | Yes | CSP-owned | Every release follows a defined quality path with acceptance criteria, review, automated application and database tests, staging validation and production monitoring. |
| Change Control and Configuration Management | Unauthorized Change Protection | CCC-04.1 | Is a procedure to authorize the addition, removal, update, and management of assets owned, controlled, or used by the organization, implemented and enforced? | Yes | CSP-owned | Named administrators authorize material changes to source, infrastructure, dependencies and production services. Repository and deployment histories retain the approved change record. |
| Change Control and Configuration Management | Change Agreements | CCC-05.1 | Are provisions to limit changes directly impacting service customer-owned environments (tenants) to explicitly authorized requests included within service level agreements? | Yes | Shared CSP and CSC | Customer-impacting configuration and integration changes follow agreed scope, change approval and release windows. Tenant data is not altered outside authorized product actions or approved service work. |
| Change Control and Configuration Management | Change Management Baseline | CCC-06.1 | Are change management and configuration baselines established, documented and implemented for all relevant authorized changes on organizational assets? | Yes | CSP-owned | Application, infrastructure and deployment baselines are version controlled. Reviews occur with each material change and at least annually through the ISMS. |
| Change Control and Configuration Management | Change Management Baseline | CCC-06.2 | Are the baselines reviewed and updated at least annually or upon significant changes? | Yes | CSP-owned | Application, infrastructure and deployment baselines are version controlled. Reviews occur with each material change and at least annually through the ISMS. |
| Change Control and Configuration Management | Detection of Baseline Deviation | CCC-07.1 | Are detection measures implemented with proactive notification if changes deviate from established baselines? | Yes | CSP-owned | Monitoring, deployment records, configuration review and repository history identify unexpected changes or deviations and route them to the responsible engineer. |
| Change Control and Configuration Management | Change Restoration | CCC-09.1 | Is a process to proactively roll back changes to a previously known “good state” defined and implemented in case of errors or security concerns? | Yes | CSP-owned | Deployments retain the preceding known-good build and support automated rollback. Database migrations are reviewed, tested and paired with recovery procedures appropriate to the change. |
| Cryptography, Encryption & Key Management | Encryption and Key Management Policy and Procedures | CEK-01.1 | Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | Shared CSP and third party | The security policy defines approved encryption and secret-handling principles. Cryptographic configuration is reviewed annually and after material architecture or supplier changes. |
| Cryptography, Encryption & Key Management | Encryption and Key Management Policy and Procedures | CEK-01.2 | Are cryptography, encryption, and key management policies and procedures reviewed and updated at least annually, upon significant changes? | Yes | Shared CSP and third party | The security policy defines approved encryption and secret-handling principles. Cryptographic configuration is reviewed annually and after material architecture or supplier changes. |
| Cryptography, Encryption & Key Management | CEK Roles and Responsibilities | CEK-02.1 | Are cryptography, encryption, and key management roles and responsibilities defined and implemented? | Yes | Shared CSP and third party | GreenTriangle owns application secrets, certificates and database access. Hosting and storage providers operate the underlying disk, object-storage and backup encryption controls. |
| Cryptography, Encryption & Key Management | Data Protection | CEK-03.1 | Are data protection at-rest and in-transit, and where applicable in use, provided using cryptographic libraries certified to approved standards? | Yes | Shared CSP and third party | Customer and service traffic uses current TLS implementations. Data, disks, object storage and backup repositories use provider-native AES-256 or equivalent approved encryption at rest. |
| Cryptography, Encryption & Key Management | Encryption Algorithm | CEK-04.1 | Are encryption algorithms following industry standards utilized for protecting data, based on the data classification and associated risks? | Yes | Shared CSP and third party | TLS 1.2 or later, TLS 1.3 for database traffic, and AES-256 or equivalent at rest are selected according to data sensitivity and provider-supported standards. |
| Cryptography, Encryption & Key Management | Encryption Change Management | CEK-05.1 | Are standard change management procedures established to review, approve, implement and communicate cryptography, encryption, and key management technology changes that accommodate internal and external sources? | Yes | CSP-owned | Cryptographic, certificate and secret-management changes follow the reviewed change process, staging checks and controlled production promotion. |
| Cryptography, Encryption & Key Management | Key Generation | CEK-10.1 | Are cryptographic keys generated using industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications? | Yes | Shared CSP and third party | Keys and certificates are generated using established operating-system, certificate-authority and cloud-provider cryptographic libraries and random-number sources. |
| Cryptography, Encryption & Key Management | Key Rotation | CEK-12.1 | Are cryptographic keys rotated based on a cryptoperiod calculated while considering information disclosure risks and legal and regulatory requirements? | Yes | Shared CSP and third party | Certificates, service credentials and managed encryption keys follow defined lifecycles and provider rotation facilities. Rotation is accelerated for exposure, role change or material risk. |
| Cryptography, Encryption & Key Management | Key Revocation | CEK-13.1 | Are cryptographic keys revoked and removed before the end of the established cryptoperiod (when a key is compromised, or an entity is no longer part of the organization) per defined, implemented, and evaluated processes, procedures, and technical measures to include legal and regulatory requirement provisions? | Yes | Shared CSP and third party | Compromised, obsolete or ownerless credentials and keys are revoked promptly; related sessions are invalidated and replacements are issued through the controlled secret process. |
| Cryptography, Encryption & Key Management | Key Destruction | CEK-14.1 | Are processes, procedures and technical measures to securely destroy cryptographic keys when they are no longer needed, defined, implemented, and evaluated, and include provisions for legal and regulatory requirements? | Yes | Shared CSP and third party | Retired secrets and keys are deleted from active stores and deployments. Provider-managed keys follow the provider lifecycle and deletion controls, subject to legal retention. |
| Datacenter Security | Secure Area Policy and Procedures | DCS-04.1 | Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, enforced, and maintained? | Yes | Shared CSP and third party | GreenTriangle is a remote organization with a documented endpoint and private-workspace baseline. Certified hosting providers operate physical datacentre security, safety and environmental controls and review them under their assurance programmes. |
| Datacenter Security | Secure Area Policy and Procedures | DCS-04.2 | Are policies and procedures for maintaining safe, secure working environments (e.g., offices, rooms) reviewed and updated at least annually, or upon significant changes? | Yes | Shared CSP and third party | GreenTriangle is a remote organization with a documented endpoint and private-workspace baseline. Certified hosting providers operate physical datacentre security, safety and environmental controls and review them under their assurance programmes. |
| Datacenter Security | Assets Classification | DCS-06.1 | Is the classification and documentation of physical and logical assets based on the organizational business risk? | Yes | Shared CSP and third party | Logical services, data stores, endpoints and supplier-hosted assets are classified by service criticality, data sensitivity and risk; classifications are reviewed with the risk register and material changes. |
| Datacenter Security | Assets Classification | DCS-06.2 | Are assets’ classifications reviewed and updated at least annually or upon significant changes? | Yes | Shared CSP and third party | Logical services, data stores, endpoints and supplier-hosted assets are classified by service criticality, data sensitivity and risk; classifications are reviewed with the risk register and material changes. |
| Datacenter Security | Assets Cataloguing and Tracking | DCS-07.1 | Are all relevant physical and logical assets at all CSP sites cataloged and tracked within a secured system? | Yes | Shared CSP and third party | Critical hosts, services, data stores, endpoints, locations and owners are recorded in controlled inventories and version-controlled operational configuration. Reviews occur at least annually and after material changes. |
| Datacenter Security | Assets Cataloguing and Tracking | DCS-07.2 | Is the catalogue reviewed and updated at least annually or upon significant changes? | Yes | Shared CSP and third party | Critical hosts, services, data stores, endpoints, locations and owners are recorded in controlled inventories and version-controlled operational configuration. Reviews occur at least annually and after material changes. |
| Data Security and Privacy Lifecycle Management | Security and Privacy Policy and Procedures | DSP-01.1 | Are policies and procedures established, documented, approved, communicated, enforced, evaluated, and maintained for the preparation, classification, protection, and handling of data throughout its lifecycle according to all applicable laws and regulations, standards, and risk level? | Yes | CSP-owned | Data-security and privacy controls cover collection, purpose, classification, access, transmission, storage, retention, export and deletion. They are reviewed annually and following material legal, customer or architecture changes. |
| Data Security and Privacy Lifecycle Management | Security and Privacy Policy and Procedures | DSP-01.2 | Are data security and privacy policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Data-security and privacy controls cover collection, purpose, classification, access, transmission, storage, retention, export and deletion. They are reviewed annually and following material legal, customer or architecture changes. |
| Data Security and Privacy Lifecycle Management | Data Inventory | DSP-03.1 | Is a data inventory created and maintained for sensitive, regulated and personal information (at a minimum)? | Yes | CSP-owned | Data categories, purposes, systems, locations, access and subprocessors are maintained in the processing and service inventories and reviewed at least annually and after changes. |
| Data Security and Privacy Lifecycle Management | Data Inventory | DSP-03.2 | Is the inventory reviewed and updated at least annually or upon significant changes? | Yes | CSP-owned | Data categories, purposes, systems, locations, access and subprocessors are maintained in the processing and service inventories and reviewed at least annually and after changes. |
| Data Security and Privacy Lifecycle Management | Data Classification | DSP-04.1 | Is data classified according to type and sensitivity levels? | Yes | CSP-owned | Information is classified according to sensitivity, customer ownership, personal-data status and operational criticality, with handling controls matched to the classification. |
| Data Security and Privacy Lifecycle Management | Data Flow Documentation | DSP-05.1 | Is data flow documentation created to identify what data is processed and where it is stored and transmitted? | Yes | CSP-owned | Architecture and data-flow records identify collection, APIs, application processing, PostgreSQL, object storage, monitoring, backups and approved integrations. They are reviewed with material releases and at least annually. |
| Data Security and Privacy Lifecycle Management | Data Flow Documentation | DSP-05.2 | Is data flow documentation reviewed at defined intervals, at least annually, or upon significant changes? | Yes | CSP-owned | Architecture and data-flow records identify collection, APIs, application processing, PostgreSQL, object storage, monitoring, backups and approved integrations. They are reviewed with material releases and at least annually. |
| Data Security and Privacy Lifecycle Management | Data Ownership and Stewardship | DSP-06.1 | Is the ownership and stewardship of all relevant personal and sensitive data documented? | Yes | Shared CSP and CSC | Customers retain ownership of their business data. GreenTriangle assigns service stewardship and operational ownership; contracts and DPAs define controller, processor and authorized-user responsibilities. |
| Data Security and Privacy Lifecycle Management | Data Ownership and Stewardship | DSP-06.2 | Is data ownership and stewardship documentation reviewed at least annually? | Yes | Shared CSP and CSC | Customers retain ownership of their business data. GreenTriangle assigns service stewardship and operational ownership; contracts and DPAs define controller, processor and authorized-user responsibilities. |
| Data Security and Privacy Lifecycle Management | Data Protection by Design and Default | DSP-07.1 | Are systems, products, and business practices based on security principles by design and per industry best practices? | Yes | CSP-owned | Security by design is supported by threat and risk review, least privilege, tenant isolation, encryption, reviewed changes, automated testing, monitoring, backup and recovery. |
| Data Security and Privacy Lifecycle Management | Data Privacy by Design and Default | DSP-08.1 | Are systems, products, and business practices based on privacy principles by design and according to industry best practices? | Yes | Shared CSP and CSC | The service minimizes personal data, uses restrictive default access and allows customer administrators to assign roles. Processing follows documented purposes and applicable privacy law. |
| Data Security and Privacy Lifecycle Management | Data Privacy by Design and Default | DSP-08.2 | Are systems’ privacy settings configured by default and according to all applicable laws and regulations? | Yes | Shared CSP and CSC | The service minimizes personal data, uses restrictive default access and allows customer administrators to assign roles. Processing follows documented purposes and applicable privacy law. |
| Data Security and Privacy Lifecycle Management | Sensitive Data Transfer | DSP-10.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope (as permitted by respective laws and regulations)? | Yes | Shared CSP and CSC | Sensitive transfers use authenticated TLS channels and approved integrations. Authorization, customer scope and purpose limit each transfer; secrets and sensitive values are excluded from logs and evidence. |
| Data Security and Privacy Lifecycle Management | Personal Data Access, Reversal, Rectification and Deletion | DSP-11.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to enable data subjects to request access to, modify, or delete personal data (per applicable laws and regulations)? | Yes | Shared CSP and CSC | Data-subject requests are routed through the customer/controller or GreenTriangle privacy contact as appropriate. Search, correction, export and deletion actions are supported through controlled application and administrative procedures. |
| Data Security and Privacy Lifecycle Management | Limitation of Purpose in Personal Data Processing | DSP-12.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure personal data is processed (per applicable laws and regulations and for the purposes declared to the data subject)? | Yes | Shared CSP and CSC | Personal data is processed only for documented service purposes, contractual delivery, support and applicable legal duties. Product design minimizes the personal data required. |
| Data Security and Privacy Lifecycle Management | Personal Data Sub-processing | DSP-13.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated for the transfer and sub-processing of personal data within the service supply chain (according to any applicable laws and regulations)? | Yes | Shared CSP and third party | Subprocessing is governed through DPAs, an EU/EEA location and subprocessor register, access restrictions and supplier review. Material changes follow contractual notification requirements. |
| Data Security and Privacy Lifecycle Management | Disclosure of Data Sub-processors | DSP-14.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to disclose details to the data owner of any personal or sensitive data access by sub-processors before processing initiation? | Yes | Shared CSP and CSC | Customers receive the applicable subprocessor and location information before processing and are informed of material changes through the contractual process. |
| Data Security and Privacy Lifecycle Management | Data Retention and Deletion | DSP-16.1 | Do data retention, archiving, and deletion practices follow business requirements, applicable laws, and regulations? | Yes | Shared CSP and CSC | Retention and deletion follow contract, customer instruction, legal obligations and documented backup expiry. Exit procedures provide validated exports and controlled deletion after the agreed retention period. |
| Data Security and Privacy Lifecycle Management | Sensitive Data Protection | DSP-17.1 | Are processes, procedures, and technical measures defined and implemented to protect sensitive data throughout its lifecycle? | Yes | CSP-owned | Sensitive data is protected through minimization, role-based access, tenant isolation, encryption, restricted administration, audit, secure transfer, backup and controlled deletion. |
| Data Security and Privacy Lifecycle Management | Data Location | DSP-19.1 | Are processes, procedures, and technical measures defined and implemented to specify and document physical data locations, including locales where data is processed or backed up? | Yes | Shared CSP and third party | Production and backup locations are recorded in the service and subprocessor register. Core processing and storage remain in the EU/EEA, with current application, database and backup locations documented for customer review. |
| Governance, Risk and Compliance | Governance Program Policy and Procedures | GRC-01.1 | Are information governance program policies and procedures sponsored by organizational leadership established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Controlled policies, evidence and metrics are maintained in the ISMS. |
| Governance, Risk and Compliance | Governance Program Policy and Procedures | GRC-01.2 | Are the policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Controlled policies, evidence and metrics are maintained in the ISMS. |
| Governance, Risk and Compliance | Risk Management Program | GRC-02.1 | Is there an established and maintained formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of risks? | Yes | CSP-owned | A leadership-sponsored risk methodology and register define identification, likelihood, impact, ownership, treatment, residual-risk acceptance and review triggers. |
| Governance, Risk and Compliance | Governance Responsibility Model | GRC-06.1 | Are roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs defined and documented? | Yes | CSP-owned | The CEO/CTO is the ISMS and risk owner. Engineering, operations, privacy, service and control responsibilities are assigned through policies, operating procedures and delivery roles. |
| Governance, Risk and Compliance | Information System Regulatory Mapping | GRC-07.1 | Are all relevant standards, regulations, legal/contractual, and statutory requirements applicable to your organization identified and documented? | Yes | CSP-owned | Applicable legal, regulatory, privacy, contractual and customer-security requirements are recorded and reviewed at least annually and when entering a new jurisdiction or material contract. |
| Governance, Risk and Compliance | Information System Regulatory Mapping | GRC-07.2 | Are the identified requirements reviewed at least annually or upon significant changes? | Yes | CSP-owned | Applicable legal, regulatory, privacy, contractual and customer-security requirements are recorded and reviewed at least annually and when entering a new jurisdiction or material contract. |
| Human Resources | Clean Desk Policy and Procedures | HRS-03.1 | Are policies and procedures requiring unattended workspaces to conceal confidential data established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Remote-working rules require private work areas, locked screens and protection of confidential information from household members, visitors and public view. The policy is reviewed annually and after material changes. |
| Human Resources | Clean Desk Policy and Procedures | HRS-03.2 | Are policies and procedures requiring unattended workspaces to conceal confidential data reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Remote-working rules require private work areas, locked screens and protection of confidential information from household members, visitors and public view. The policy is reviewed annually and after material changes. |
| Human Resources | Remote and Home Working Policy and Procedures | HRS-04.1 | Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Remote access requires approved endpoints, MFA, encrypted connections, VPN for administration, restricted company services and incident reporting. The baseline is reviewed annually and after material changes. |
| Human Resources | Remote and Home Working Policy and Procedures | HRS-04.2 | Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Remote access requires approved endpoints, MFA, encrypted connections, VPN for administration, restricted company services and incident reporting. The baseline is reviewed annually and after material changes. |
| Human Resources | Security Awareness Training | HRS-11.1 | Is a security awareness training program for all employees of the organization established, documented, approved, communicated, applied, evaluated and maintained? | Yes | CSP-owned | All personnel receive continuous security awareness through onboarding, operational briefings and security findings. Engineers receive additional secure-development reinforcement through peer code review against documented review rules. Review outcomes, findings and incidents are used to update the programme. |
| Human Resources | Security Awareness Training | HRS-11.2 | Are regular security awareness training updates provided? | Yes | CSP-owned | Security updates are provided continuously through onboarding, peer code review, engineering security reviews, vulnerability notices and operational briefings. The ISO programme consolidates participation and effectiveness evidence. |
| Identity & Access Management | Identity and Access Management Policy and Procedures | IAM-01.1 | Are identity and access management policies and procedures established, documented, approved, communicated, implemented, applied, evaluated, and maintained? | Yes | CSP-owned | Identity and access procedures cover named accounts, MFA, role assignment, least privilege, provisioning, periodic review and prompt revocation. They are reviewed annually and after material changes. |
| Identity & Access Management | Identity and Access Management Policy and Procedures | IAM-01.2 | Are identity and access management policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Identity and access procedures cover named accounts, MFA, role assignment, least privilege, provisioning, periodic review and prompt revocation. They are reviewed annually and after material changes. |
| Identity & Access Management | Identity Inventory | IAM-03.1 | Is the inventory of identities managed, stored, and regularly reviewed, and is their level of access monitored? | Yes | CSP-owned | Named workforce, service, customer and privileged identities and their access levels are recorded in the relevant identity, infrastructure and application systems and reviewed periodically. |
| Identity & Access Management | Separation of Duties | IAM-04.1 | Is the separation of duties principle employed when implementing information system access? | Yes | CSP-owned | Separation is applied between development, review, release and customer administration where practical. Small-team constraints use independent review, named approval and traceable records. |
| Identity & Access Management | Least Privilege | IAM-05.1 | Is the least privilege principle employed when implementing information system access? | Yes | CSP-owned | Keycloak roles, customer groups, database row-level security, scoped cloud roles and restricted administrative paths apply least privilege to application and infrastructure access. |
| Identity & Access Management | Access Provisioning | IAM-06.1 | Is an identity access provisioning process defined and implemented which authorizes, records, and communicates data and assets access changes? | Yes | Shared CSP and CSC | Access is requested or authorized by the responsible owner, assigned to a named identity, recorded in the relevant system and communicated to the user. Customer administrators control their nominated users and roles. |
| Identity & Access Management | Access Changes and Revocation | IAM-07.1 | Is a process in place to de-provision or modify identity access in a timely manner? | Yes | Shared CSP and CSC | Leaver and role-change procedures revoke sessions, credentials, VPN, repository, cloud and application access promptly. Customer administrators manage customer-user changes with supplier support where required. |
| Identity & Access Management | Access Review | IAM-08.1 | Are reviews and revalidation of identity access for least privilege and separation of duties completed with a frequency commensurate with organizational risk tolerance, and at least annually or upon significant changes? | Yes | Shared CSP and CSC | Privileged and workforce access is reviewed according to risk and at least annually; customer administrators review their own user population and role assignments. |
| Identity & Access Management | Segregation of Privileged Access Roles | IAM-09.1 | Are processes, procedures, and technical measures for the segregation of privileged access roles defined, implemented, and evaluated? | Yes | CSP-owned | Privileged access uses named accounts, separate infrastructure roles, VPN-restricted administration, MFA where supported and recorded changes. Application administration is separated from ordinary user roles. |
| Identity & Access Management | Management of Privileged Access Roles | IAM-10.1 | Is an access process defined and implemented to ensure privileged access roles and rights are granted for a limited period? | Yes | CSP-owned | The controlled process is operational. Standing privileged grants are limited to 12 months and require positive renewal; temporary grants expire when the task ends and normally within seven days. Reviews run quarterly, after role changes and immediately for leavers. |
| Identity & Access Management | Management of Privileged Access Roles | IAM-10.2 | Are procedures implemented to prevent the accumulation of segregated privileged access? | Yes | CSP-owned | Named accounts, least privilege, role separation and periodic access review prevent incompatible privileged rights from accumulating. Access is removed when responsibilities change. |
| Identity & Access Management | Strong Authentication | IAM-13.1 | Are processes, procedures, and technical measures for authenticating access to systems, application, and data assets including multifactor authentication for a least-privileged user and sensitive data access defined, implemented, and evaluated? | Yes | Shared CSP and third party | Keycloak provides OAuth 2.0/OIDC authentication, MFA and certificate-backed TLS. Workforce access to key services requires MFA, and service identities use certificates, signed tokens or protected credentials. |
| Identity & Access Management | Strong Authentication | IAM-13.2 | Are digital certificates or alternatives that achieve an equivalent security level for system identities adopted? | Yes | Shared CSP and third party | Keycloak provides OAuth 2.0/OIDC authentication, MFA and certificate-backed TLS. Workforce access to key services requires MFA, and service identities use certificates, signed tokens or protected credentials. |
| Interoperability & Portability | Interoperability and Portability Policy and Procedures | IPY-01.1 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for communications between application interfaces (e.g., APIs)? | Yes | Shared CSP and CSC | Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change. |
| Interoperability & Portability | Interoperability and Portability Policy and Procedures | IPY-01.2 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information processing interoperability? | Yes | Shared CSP and CSC | Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change. |
| Interoperability & Portability | Interoperability and Portability Policy and Procedures | IPY-01.3 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for application development portability? | Yes | Shared CSP and CSC | Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change. |
| Interoperability & Portability | Interoperability and Portability Policy and Procedures | IPY-01.4 | Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information/data exchange, usage, portability, integrity, and persistence? | Yes | Shared CSP and CSC | Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change. |
| Interoperability & Portability | Interoperability and Portability Policy and Procedures | IPY-01.5 | Are interoperability and portability policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | Shared CSP and CSC | Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change. |
| Infrastructure Security | Network Security | I&S-03.1 | Are communications between environments, services, and applications monitored? | Yes | CSP-owned | Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually. |
| Infrastructure Security | Network Security | I&S-03.2 | Are communications between environments, services, and applications encrypted? | Yes | CSP-owned | Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually. |
| Infrastructure Security | Network Security | I&S-03.3 | Are communications between environments, services, and applications restricted to only authenticated and authorized connections, as justified by the business? | Yes | CSP-owned | Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually. |
| Infrastructure Security | Network Security | I&S-03.4 | Are network configurations reviewed at least annually? | Yes | CSP-owned | Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually. |
| Infrastructure Security | Network Security | I&S-03.5 | Are network configurations supported by the documented justification of all allowed services, protocols, ports, and compensating controls? | Yes | CSP-owned | Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually. |
| Infrastructure Security | OS Hardening and Base Controls | I&S-04.1 | Is every host and guest OS, hypervisor, or infrastructure control plane hardened (according to their respective best practices) and supported by technical controls as part of a security baseline? | Yes | Shared CSP and third party | Supported operating systems, minimal exposed services, default-deny host firewalls, automated security updates, container controls and provider hardening form the infrastructure baseline. |
| Infrastructure Security | Segmentation and Segregation | I&S-06.1 | Are applications and infrastructures designed, developed, deployed, and configured such that service customer (tenant) access is appropriately segmented, segregated, monitored, and restricted? | Yes | CSP-owned | Customer access is segmented through Keycloak groups and roles, tenant-aware APIs, database row-level security, object authorization and monitored administrative paths. |
| Infrastructure Security | Migration to Cloud Environments | I&S-07.1 | Are secure and encrypted communication channels including only up-to-date and approved protocols used when migrating servers, services, applications, or data to cloud environments? | Yes | CSP-owned | Server, service and data migrations use authenticated encrypted channels, approved protocols, controlled credentials and validation before cutover. |
| Infrastructure Security | Network Defense | I&S-09.1 | Are processes, procedures, and defense-in-depth techniques defined, implemented, and evaluated for protection, detection, and timely response to network-based attacks? | Yes | Shared CSP and third party | Defense in depth combines provider edge controls, default-deny firewalls, rate controls, CrowdSec threat detection and blocking, TLS, restricted administration, monitoring and incident procedures. |
| Logging and Monitoring | Logging and Monitoring Policy and Procedures | LOG-01.1 | Are logging and monitoring policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Logging and monitoring policies cover application, infrastructure, authentication, administration, integrations, jobs, backups and security events. Coverage is reviewed annually and after material changes. |
| Logging and Monitoring | Logging and Monitoring Policy and Procedures | LOG-01.2 | Are policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Logging and monitoring policies cover application, infrastructure, authentication, administration, integrations, jobs, backups and security events. Coverage is reviewed annually and after material changes. |
| Logging and Monitoring | Audit Logs Access and Accountability | LOG-04.1 | Is audit log access restricted to authorized identities, and are records of that access maintained? | Yes | CSP-owned | Operational and audit-log access is limited to authorized personnel and protected service roles. Administrative access and relevant log actions are recorded. |
| Logging and Monitoring | Audit Logs Monitoring and Response | LOG-05.1 | Are capabilities implemented and maintained to correlate and monitor security audit logs for the detection of suspicious or anomalous activity that deviates from typical or expected patterns? | Yes | CSP-owned | Central metrics and alerts cover availability, HTTP errors, capacity, backup age, replication, queues and jobs. CrowdSec analyzes security events and detected anomalies are reviewed and escalated. |
| Logging and Monitoring | Audit Logs Monitoring and Response | LOG-05.2 | Is a process established and followed to review and take appropriate and timely actions on detected anomalies? | Yes | CSP-owned | Central metrics and alerts cover availability, HTTP errors, capacity, backup age, replication, queues and jobs. CrowdSec analyzes security events and detected anomalies are reviewed and escalated. |
| Logging and Monitoring | Audit Logs Sanitization | LOG-08.1 | Are technical measures defined, implemented, and evaluated to enable service customers to detect and scrub or tokenize sensitive data from logs, in order to prevent unauthorized exposure as per applicable laws and regulations? | N/A | CSP-owned | Customers do not receive unrestricted raw infrastructure logs. GreenTriangle masks or excludes sensitive values before logging and provides customer audit records and exports containing only approved fields. |
| Security Incident Management, E-Discovery, & Cloud Forensics | Incident Response Plans | SEF-03.1 | Is a security incident response plan that includes a communication strategy for notifying relevant internal departments, impacted service customers, and other business-critical relationships (such as supply-chain) established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | The incident process defines contacts, severity, containment, customer and supplier communication, legal assessment, recovery and follow-up. Customer notification follows applicable law, contract and incident impact. |
| Security Incident Management, E-Discovery, & Cloud Forensics | Incident Response Testing | SEF-04.1 | Is a structured approach followed to evaluate the effectiveness of incident response plans at planned intervals or upon significant changes? | Yes | CSP-owned | A structured exercise on 23 January 2025 tested response to PostgreSQL unavailability against the business continuity plan. It recorded the scenario, timeline, 2-hour-46-minute recovery, result against the four-hour objective, evidence limitations and assigned follow-up actions. Authenticated web and API security testing followed in August 2026. |
| Security Incident Management, E-Discovery, & Cloud Forensics | Incident Management and Response | SEF-07.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated for timely and effective response to security incidents in accordance with incident categories and severity levels? | Yes | CSP-owned | Monitoring and incident contacts support severity-based triage, containment, recovery, customer communication and corrective action. Procedures are reviewed annually and after material incidents or changes. |
| Security Incident Management, E-Discovery, & Cloud Forensics | Incident Management and Response | SEF-07.2 | Are these processes and procedures reviewed, updated, and tested at least annually? | Yes | CSP-owned | Monitoring and incident contacts support severity-based triage, containment, recovery, customer communication and corrective action. Procedures are reviewed annually and after material incidents or changes. |
| Security Incident Management, E-Discovery, & Cloud Forensics | Security Breach Notification | SEF-08.1 | Are processes, procedures, and technical measures for security breach notifications defined and implemented? | Yes | Shared CSP and third party | Material incidents and relevant supplier incidents are assessed and reported under applicable GDPR, contractual and regulatory timelines, with affected customers receiving status and impact information. |
| Security Incident Management, E-Discovery, & Cloud Forensics | Security Breach Notification | SEF-08.2 | Are material security breaches reported (including any relevant supply chain breaches) as per applicable SLAs, laws, and regulations? | Yes | Shared CSP and third party | Material incidents and relevant supplier incidents are assessed and reported under applicable GDPR, contractual and regulatory timelines, with affected customers receiving status and impact information. |
| Supply Chain Management, Transparency, and Accountability | Supply Chain Risk Management Policies and Procedures | STA-01.1 | Are policies and procedures for supply chain risk management established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Supply-chain governance records critical suppliers, service purpose, data access, location, assurance, contractual safeguards, owner and review. It is reviewed annually and after significant supplier changes. |
| Supply Chain Management, Transparency, and Accountability | Supply Chain Risk Management Policies and Procedures | STA-01.2 | Are policies and procedures for supply chain risk management reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Supply-chain governance records critical suppliers, service purpose, data access, location, assurance, contractual safeguards, owner and review. It is reviewed annually and after significant supplier changes. |
| Supply Chain Management, Transparency, and Accountability | SSRM Supply Chain | STA-03.1 | Is the SSRM applied, documented, implemented, and managed throughout the supply chain? | Yes | Shared CSP and third party | The shared-responsibility model distinguishes GreenTriangle application and operational controls from hosting, storage, monitoring and other supplier controls while retaining supplier accountability. |
| Supply Chain Management, Transparency, and Accountability | SSRM Control Ownership | STA-05.1 | Is the shared ownership and applicability of all CSA CCM controls delineated according to the SSRM? | Yes | Shared CSP and third party | This CAIQ records whether GreenTriangle, the customer or a third party performs each control. Contracts, DPAs and service documentation assign customer and supplier duties. |
| Supply Chain Management, Transparency, and Accountability | Supply Chain Inventory | STA-08.1 | Is an inventory of all supply chain relationships developed and maintained? | Yes | CSP-owned | A controlled supplier and subprocessor inventory records each relationship, service, data access, processing location, assurance, contract owner and review status. |
| Threat & Vulnerability Management | Malware and Malicious Instructions Protection Policy and Procedures | TVM-02.1 | Are policies and procedures to protect against malware and malicious instructions established, documented, approved, communicated, applied, evaluated, and maintained? | Yes | CSP-owned | Endpoint platform protection, dependency controls, reviewed software, restricted server services and security updates protect against malware and malicious instructions. Policies are reviewed annually and after material changes. |
| Threat & Vulnerability Management | Malware and Malicious Instructions Protection Policy and Procedures | TVM-02.2 | Are asset management and malware protection policies and procedures reviewed and updated at least annually, or upon significant changes? | Yes | CSP-owned | Endpoint platform protection, dependency controls, reviewed software, restricted server services and security updates protect against malware and malicious instructions. Policies are reviewed annually and after material changes. |
| Threat & Vulnerability Management | Vulnerability Identification | TVM-03.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated for vulnerability detection on organizationally managed assets at least monthly? | Yes | CSP-owned | Automated dependency and source checks run with code changes, supported by infrastructure review and periodic dynamic testing. Authenticated web and API testing in August 2026 reported no High-risk findings. |
| Threat & Vulnerability Management | Detection Updates | TVM-05.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to update detection tools, threat signatures, and compromise indicators weekly (or more frequent) basis? | Yes | Shared CSP and third party | Operating-system, CrowdSec, browser and endpoint protections use maintained threat intelligence and signatures. Dependency and vulnerability sources update continuously or with each scan. |
| Threat & Vulnerability Management | Vulnerability Remediation Schedule | TVM-08.1 | Are processes, procedures and technical measures defined, implemented and evaluated based on identified risks to support scheduled and emergency responses to vulnerability identification? | Yes | CSP-owned | Findings are prioritized using severity, exploitability, exposure and customer impact. Emergency releases support urgent containment and correction; every material correction is reviewed and retested. |
| Threat & Vulnerability Management | Threat Response | TVM-10.1 | Is a risk-based method used for the prioritization and mitigation of threats, leveraging an industry-recognized framework to guide threat decision-making and protection measures? | Yes | CSP-owned | Threat and vulnerability decisions use the ISMS risk method, OWASP guidance, CVSS where applicable and business-impact analysis. |
| Threat & Vulnerability Management | Vulnerability Management Reporting | TVM-11.1 | Is a process defined and implemented to track and report vulnerability identification and remediation activities that include stakeholder notification? | Yes | CSP-owned | Findings, owners, severity, correction, exceptions and retest evidence are tracked. The August 2026 authenticated testing and source and configuration review through an external security platform provider produced no High or Critical findings. |
| Universal Endpoint Management | Application and Service Approval | UEM-02.1 | Is there a defined, documented, applicable and evaluated list containing approved services, applications, and the sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data? | Yes | CSP-owned | The endpoint baseline restricts access to approved company services, applications and sources and prohibits unapproved software or browser extensions for company-data access. |
| Universal Endpoint Management | Endpoint Inventory | UEM-04.1 | Is an inventory of all endpoints used and maintained to store, access and process company data? | Yes | CSP-owned | Employee and approved contractor endpoints used for company access are inventoried with custodian, ownership, device identifier, operating-system version, access class and verification date. |
| Universal Endpoint Management | Endpoint Management | UEM-05.1 | Are processes, procedures, and technical measures defined, implemented and evaluated, to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data? | Yes | CSP-owned | Endpoint controls require supported macOS, security updates, FileVault, individual accounts, automatic locking, native malware protection, MFA, VPN administration and approved storage. |
| Universal Endpoint Management | Automatic Lock Screen | UEM-06.1 | Are all relevant interactive-use endpoints configured to require an automatic lock screen? | Yes | CSP-owned | Interactive endpoints require automatic screen locking after no more than ten minutes and a password-protected individual account. |
| Universal Endpoint Management | Anti-Malware Detection and Prevention | UEM-09.1 | Are anti-malware detection and prevention technology services configured on managed endpoints? | Yes | CSP-owned | Managed Mac endpoints retain Apple Gatekeeper and XProtect and receive supported operating-system and security updates. |
| Universal Endpoint Management | Software Firewall | UEM-10.1 | Are software firewalls configured on managed endpoints? | Yes | CSP-owned | Endpoint software firewalls are enabled as part of the device baseline, with network administration additionally restricted through the company VPN. |
| Universal Endpoint Management | Remote Wipe | UEM-13.1 | Are processes, procedures, and technical measures defined, implemented, and evaluated to enable remote company data deletion on managed endpoint devices? | Yes | CSP-owned | Apple Business Manager-backed device management enables centralized remote lock and wipe on managed company endpoints. Enrollment is being rolled out across the company device inventory; loss or offboarding also triggers immediate credential and session revocation. |
Source framework: Cloud Security Alliance CCM-Lite and CAIQ-Lite v4.1.0.