Cloud security self-assessment

We use the Cloud Security Alliance CAIQ-Lite v4.1.0 to describe our cloud security controls and shared responsibilities.

Last updated August 2026

This self-assessment covers GreenTriangle AG and the unified GT SaaS platform. It uses CAIQ-Lite v4.1.0, based on the Cloud Security Alliance Cloud Controls Matrix v4.1. The current CAIQ-Lite contains 138 questions across 17 domains. Answers describe controls operating on 27 August 2026 and the shared responsibilities of GreenTriangle, its service providers and customers.

Response summary: 137 Yes; 0 No; 1 N/A.

The August 2026 assurance cycle included authenticated web and API testing and a source and configuration review through an external security platform provider. Neither produced a High or Critical finding. Medium and lower observations remain subject to the normal findings, correction and retest process. This CAIQ is a supplier self-assessment.

Domain Control ID Question Answer Ownership Implementation
Audit & Assurance Independent Assessments A&A-02.1 Are independent audit and assurance assessments conducted according to relevant standards at least annually? Yes Shared CSP and third party Independent annual assurance covers the EU hosting and cloud providers used by the service.
Audit & Assurance Risk Based Planning Assessment A&A-03.1 Are independent audit and assurance assessments performed according to risk-based plans and policies, and in response to significant changes or emerging risks? Yes Shared CSP and third party Security reviews follow the risk register and are repeated after material changes. The 2026 assurance cycle included authenticated web and API testing, source and configuration review through an external security platform provider, and infrastructure-provider assurance checks.
Audit & Assurance Requirements Compliance A&A-04.1 Is compliance verified regarding all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit? Yes CSP-owned Applicable legal, privacy, contractual and security obligations are reviewed through the ISMS, customer due diligence, DPAs and contract approval.
Audit & Assurance Remediation A&A-06.1 Is a risk-based corrective action plan to remediate audit findings established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Findings are recorded with severity, owner, target date, correction and retest evidence. Critical findings are contained within four hours and corrected within seven days; High findings are corrected within 30 days.
Audit & Assurance Remediation A&A-06.2 Is the remediation status of audit findings regularly reviewed and reported to relevant stakeholders? Yes CSP-owned Findings are recorded with severity, owner, target date, correction and retest evidence. Critical findings are contained within four hours and corrected within seven days; High findings are corrected within 30 days.
Application & Interface Security Application Security Baseline Requirements AIS-02.1 Are baseline requirements to secure applications established, documented, and maintained? Yes CSP-owned Application baselines require reviewed changes, secure authentication and authorization, tenant isolation, input validation, protected secrets, automated tests and staging validation.
Application & Interface Security Secure Application Development Lifecycle AIS-04.1 Is a secure SDLC process defined and implemented for application requirements analysis, planning, design, development, testing, deployment, and operation per organizationally designed security requirements? Yes CSP-owned The SDLC covers requirements, design, peer review, automated testing, database validation, security checks, staged release, production monitoring and rollback.
Application & Interface Security Secure Application Deployment AIS-06.1 Are strategies and capabilities established and implemented to deploy application code in a secure, standardized, and compliant manner? Yes CSP-owned Version-controlled pipelines build, test and deploy approved releases to staging and production. Production promotion is controlled and an automated rollback path retains the last known-good release.
Application & Interface Security Secure Application Deployment AIS-06.2 Is the deployment and integration of application code automated where possible? Yes CSP-owned Version-controlled pipelines build, test and deploy approved releases to staging and production. Production promotion is controlled and an automated rollback path retains the last known-good release.
Application & Interface Security Application Vulnerability Remediation AIS-07.1 Are application security vulnerabilities remediated following defined processes? Yes CSP-owned Application and dependency findings are triaged by risk, corrected through the normal reviewed release process and retested. Automated checks support detection and safe dependency updates.
Application & Interface Security Application Vulnerability Remediation AIS-07.2 Is the remediation of application security vulnerabilities automated when possible? Yes CSP-owned Application and dependency findings are triaged by risk, corrected through the normal reviewed release process and retested. Automated checks support detection and safe dependency updates.
Application & Interface Security API Security AIS-08.1 Are processes, procedures, and technical measures defined and implemented to secure APIs? Yes CSP-owned External APIs use OAuth 2.0/OIDC bearer tokens, authorization scopes, tenant-aware database controls, validation, TLS, audit records and rate controls. Versioned customer API documentation is maintained.
Application & Interface Security API Security AIS-08.2 Are reviews and updates for any improvements conducted at least annually, or upon significant changes? Yes CSP-owned External APIs use OAuth 2.0/OIDC bearer tokens, authorization scopes, tenant-aware database controls, validation, TLS, audit records and rate controls. Versioned customer API documentation is maintained.
Business Continuity Management and Operational Resilience Business Continuity Management Policy and Procedures BCR-01.1 Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned A version-controlled business continuity plan defines critical services, recovery responsibilities, communications, RTO/RPO targets and periodic review after material changes.
Business Continuity Management and Operational Resilience Business Continuity Management Policy and Procedures BCR-01.2 Are the policies and procedures reviewed and updated at least annually, or upon significant changes? Yes CSP-owned A version-controlled business continuity plan defines critical services, recovery responsibilities, communications, RTO/RPO targets and periodic review after material changes.
Business Continuity Management and Operational Resilience Risk Assessment and Impact Analysis BCR-02.1 Are criteria for developing business continuity and operational resiliency strategies and capabilities established based on business disruption and risk impacts? Yes CSP-owned The continuity analysis ranks critical services and considers personnel, hosting, database, storage, authentication and remote-sensing dependencies. It is reviewed with the risk register and material architecture changes.
Business Continuity Management and Operational Resilience Risk Assessment and Impact Analysis BCR-02.2 Are the risk assessment and impact analysis reviewed and updated at least annually or upon significant changes? Yes CSP-owned The continuity analysis ranks critical services and considers personnel, hosting, database, storage, authentication and remote-sensing dependencies. It is reviewed with the risk register and material architecture changes.
Business Continuity Management and Operational Resilience Business Continuity Strategy BCR-03.1 Are strategies being established to reduce the impact of business disruptions, and are resiliency and recovery from business disruptions being improved? Yes Shared CSP and third party Resilience uses geographically distributed personnel, a secondary application host, PostgreSQL primary/standby, transaction-log archiving and independent EU backup repositories.
Business Continuity Management and Operational Resilience Backup BCR-08.1 Are backups performed periodically? Yes Shared CSP and third party PostgreSQL backups, continuous transaction-log archiving and object-storage backups are retained in separate EU locations. Backup age and archiving are monitored, and restoration procedures are tested.
Business Continuity Management and Operational Resilience Backup BCR-08.2 Is the confidentiality, integrity, and availability of the backup ensured? Yes Shared CSP and third party PostgreSQL backups, continuous transaction-log archiving and object-storage backups are retained in separate EU locations. Backup age and archiving are monitored, and restoration procedures are tested.
Business Continuity Management and Operational Resilience Backup BCR-08.3 Can backups be restored appropriately for resiliency? Yes Shared CSP and third party PostgreSQL backups, continuous transaction-log archiving and object-storage backups are retained in separate EU locations. Backup age and archiving are monitored, and restoration procedures are tested.
Business Continuity Management and Operational Resilience Disaster Response Plan BCR-09.1 Is a disaster response plan established, documented, approved, applied, evaluated, and maintained to ensure recovery from natural and man-made disasters? Yes Shared CSP and third party The continuity plan covers natural, technical, supplier and human disruption. It is reviewed at least annually and after significant service or risk changes.
Business Continuity Management and Operational Resilience Disaster Response Plan BCR-09.2 Is the disaster response plan updated at least annually, and when significant changes occur? Yes Shared CSP and third party The continuity plan covers natural, technical, supplier and human disruption. It is reviewed at least annually and after significant service or risk changes.
Change Control and Configuration Management Change Management Policy and Procedures CCC-01.1 Are policies and procedures for managing the risks associated with applying changes to assets owned, controlled, or used by the organization established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Change risk is controlled through version control, peer review, automated tests, staged validation, approval, traceable deployment and rollback. The process is reviewed after major delivery changes and under the ISMS cycle.
Change Control and Configuration Management Change Management Policy and Procedures CCC-01.2 Are the policies and procedures reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Change risk is controlled through version control, peer review, automated tests, staged validation, approval, traceable deployment and rollback. The process is reviewed after major delivery changes and under the ISMS cycle.
Change Control and Configuration Management Quality Testing CCC-02.1 Is a defined quality change control, approval and testing process, incorporating baselines, testing, and release standards, established, maintained and implemented? Yes CSP-owned Every release follows a defined quality path with acceptance criteria, review, automated application and database tests, staging validation and production monitoring.
Change Control and Configuration Management Unauthorized Change Protection CCC-04.1 Is a procedure to authorize the addition, removal, update, and management of assets owned, controlled, or used by the organization, implemented and enforced? Yes CSP-owned Named administrators authorize material changes to source, infrastructure, dependencies and production services. Repository and deployment histories retain the approved change record.
Change Control and Configuration Management Change Agreements CCC-05.1 Are provisions to limit changes directly impacting service customer-owned environments (tenants) to explicitly authorized requests included within service level agreements? Yes Shared CSP and CSC Customer-impacting configuration and integration changes follow agreed scope, change approval and release windows. Tenant data is not altered outside authorized product actions or approved service work.
Change Control and Configuration Management Change Management Baseline CCC-06.1 Are change management and configuration baselines established, documented and implemented for all relevant authorized changes on organizational assets? Yes CSP-owned Application, infrastructure and deployment baselines are version controlled. Reviews occur with each material change and at least annually through the ISMS.
Change Control and Configuration Management Change Management Baseline CCC-06.2 Are the baselines reviewed and updated at least annually or upon significant changes? Yes CSP-owned Application, infrastructure and deployment baselines are version controlled. Reviews occur with each material change and at least annually through the ISMS.
Change Control and Configuration Management Detection of Baseline Deviation CCC-07.1 Are detection measures implemented with proactive notification if changes deviate from established baselines? Yes CSP-owned Monitoring, deployment records, configuration review and repository history identify unexpected changes or deviations and route them to the responsible engineer.
Change Control and Configuration Management Change Restoration CCC-09.1 Is a process to proactively roll back changes to a previously known “good state” defined and implemented in case of errors or security concerns? Yes CSP-owned Deployments retain the preceding known-good build and support automated rollback. Database migrations are reviewed, tested and paired with recovery procedures appropriate to the change.
Cryptography, Encryption & Key Management Encryption and Key Management Policy and Procedures CEK-01.1 Are cryptography, encryption, and key management policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? Yes Shared CSP and third party The security policy defines approved encryption and secret-handling principles. Cryptographic configuration is reviewed annually and after material architecture or supplier changes.
Cryptography, Encryption & Key Management Encryption and Key Management Policy and Procedures CEK-01.2 Are cryptography, encryption, and key management policies and procedures reviewed and updated at least annually, upon significant changes? Yes Shared CSP and third party The security policy defines approved encryption and secret-handling principles. Cryptographic configuration is reviewed annually and after material architecture or supplier changes.
Cryptography, Encryption & Key Management CEK Roles and Responsibilities CEK-02.1 Are cryptography, encryption, and key management roles and responsibilities defined and implemented? Yes Shared CSP and third party GreenTriangle owns application secrets, certificates and database access. Hosting and storage providers operate the underlying disk, object-storage and backup encryption controls.
Cryptography, Encryption & Key Management Data Protection CEK-03.1 Are data protection at-rest and in-transit, and where applicable in use, provided using cryptographic libraries certified to approved standards? Yes Shared CSP and third party Customer and service traffic uses current TLS implementations. Data, disks, object storage and backup repositories use provider-native AES-256 or equivalent approved encryption at rest.
Cryptography, Encryption & Key Management Encryption Algorithm CEK-04.1 Are encryption algorithms following industry standards utilized for protecting data, based on the data classification and associated risks? Yes Shared CSP and third party TLS 1.2 or later, TLS 1.3 for database traffic, and AES-256 or equivalent at rest are selected according to data sensitivity and provider-supported standards.
Cryptography, Encryption & Key Management Encryption Change Management CEK-05.1 Are standard change management procedures established to review, approve, implement and communicate cryptography, encryption, and key management technology changes that accommodate internal and external sources? Yes CSP-owned Cryptographic, certificate and secret-management changes follow the reviewed change process, staging checks and controlled production promotion.
Cryptography, Encryption & Key Management Key Generation CEK-10.1 Are cryptographic keys generated using industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications? Yes Shared CSP and third party Keys and certificates are generated using established operating-system, certificate-authority and cloud-provider cryptographic libraries and random-number sources.
Cryptography, Encryption & Key Management Key Rotation CEK-12.1 Are cryptographic keys rotated based on a cryptoperiod calculated while considering information disclosure risks and legal and regulatory requirements? Yes Shared CSP and third party Certificates, service credentials and managed encryption keys follow defined lifecycles and provider rotation facilities. Rotation is accelerated for exposure, role change or material risk.
Cryptography, Encryption & Key Management Key Revocation CEK-13.1 Are cryptographic keys revoked and removed before the end of the established cryptoperiod (when a key is compromised, or an entity is no longer part of the organization) per defined, implemented, and evaluated processes, procedures, and technical measures to include legal and regulatory requirement provisions? Yes Shared CSP and third party Compromised, obsolete or ownerless credentials and keys are revoked promptly; related sessions are invalidated and replacements are issued through the controlled secret process.
Cryptography, Encryption & Key Management Key Destruction CEK-14.1 Are processes, procedures and technical measures to securely destroy cryptographic keys when they are no longer needed, defined, implemented, and evaluated, and include provisions for legal and regulatory requirements? Yes Shared CSP and third party Retired secrets and keys are deleted from active stores and deployments. Provider-managed keys follow the provider lifecycle and deletion controls, subject to legal retention.
Datacenter Security Secure Area Policy and Procedures DCS-04.1 Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, enforced, and maintained? Yes Shared CSP and third party GreenTriangle is a remote organization with a documented endpoint and private-workspace baseline. Certified hosting providers operate physical datacentre security, safety and environmental controls and review them under their assurance programmes.
Datacenter Security Secure Area Policy and Procedures DCS-04.2 Are policies and procedures for maintaining safe, secure working environments (e.g., offices, rooms) reviewed and updated at least annually, or upon significant changes? Yes Shared CSP and third party GreenTriangle is a remote organization with a documented endpoint and private-workspace baseline. Certified hosting providers operate physical datacentre security, safety and environmental controls and review them under their assurance programmes.
Datacenter Security Assets Classification DCS-06.1 Is the classification and documentation of physical and logical assets based on the organizational business risk? Yes Shared CSP and third party Logical services, data stores, endpoints and supplier-hosted assets are classified by service criticality, data sensitivity and risk; classifications are reviewed with the risk register and material changes.
Datacenter Security Assets Classification DCS-06.2 Are assets’ classifications reviewed and updated at least annually or upon significant changes? Yes Shared CSP and third party Logical services, data stores, endpoints and supplier-hosted assets are classified by service criticality, data sensitivity and risk; classifications are reviewed with the risk register and material changes.
Datacenter Security Assets Cataloguing and Tracking DCS-07.1 Are all relevant physical and logical assets at all CSP sites cataloged and tracked within a secured system? Yes Shared CSP and third party Critical hosts, services, data stores, endpoints, locations and owners are recorded in controlled inventories and version-controlled operational configuration. Reviews occur at least annually and after material changes.
Datacenter Security Assets Cataloguing and Tracking DCS-07.2 Is the catalogue reviewed and updated at least annually or upon significant changes? Yes Shared CSP and third party Critical hosts, services, data stores, endpoints, locations and owners are recorded in controlled inventories and version-controlled operational configuration. Reviews occur at least annually and after material changes.
Data Security and Privacy Lifecycle Management Security and Privacy Policy and Procedures DSP-01.1 Are policies and procedures established, documented, approved, communicated, enforced, evaluated, and maintained for the preparation, classification, protection, and handling of data throughout its lifecycle according to all applicable laws and regulations, standards, and risk level? Yes CSP-owned Data-security and privacy controls cover collection, purpose, classification, access, transmission, storage, retention, export and deletion. They are reviewed annually and following material legal, customer or architecture changes.
Data Security and Privacy Lifecycle Management Security and Privacy Policy and Procedures DSP-01.2 Are data security and privacy policies and procedures reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Data-security and privacy controls cover collection, purpose, classification, access, transmission, storage, retention, export and deletion. They are reviewed annually and following material legal, customer or architecture changes.
Data Security and Privacy Lifecycle Management Data Inventory DSP-03.1 Is a data inventory created and maintained for sensitive, regulated and personal information (at a minimum)? Yes CSP-owned Data categories, purposes, systems, locations, access and subprocessors are maintained in the processing and service inventories and reviewed at least annually and after changes.
Data Security and Privacy Lifecycle Management Data Inventory DSP-03.2 Is the inventory reviewed and updated at least annually or upon significant changes? Yes CSP-owned Data categories, purposes, systems, locations, access and subprocessors are maintained in the processing and service inventories and reviewed at least annually and after changes.
Data Security and Privacy Lifecycle Management Data Classification DSP-04.1 Is data classified according to type and sensitivity levels? Yes CSP-owned Information is classified according to sensitivity, customer ownership, personal-data status and operational criticality, with handling controls matched to the classification.
Data Security and Privacy Lifecycle Management Data Flow Documentation DSP-05.1 Is data flow documentation created to identify what data is processed and where it is stored and transmitted? Yes CSP-owned Architecture and data-flow records identify collection, APIs, application processing, PostgreSQL, object storage, monitoring, backups and approved integrations. They are reviewed with material releases and at least annually.
Data Security and Privacy Lifecycle Management Data Flow Documentation DSP-05.2 Is data flow documentation reviewed at defined intervals, at least annually, or upon significant changes? Yes CSP-owned Architecture and data-flow records identify collection, APIs, application processing, PostgreSQL, object storage, monitoring, backups and approved integrations. They are reviewed with material releases and at least annually.
Data Security and Privacy Lifecycle Management Data Ownership and Stewardship DSP-06.1 Is the ownership and stewardship of all relevant personal and sensitive data documented? Yes Shared CSP and CSC Customers retain ownership of their business data. GreenTriangle assigns service stewardship and operational ownership; contracts and DPAs define controller, processor and authorized-user responsibilities.
Data Security and Privacy Lifecycle Management Data Ownership and Stewardship DSP-06.2 Is data ownership and stewardship documentation reviewed at least annually? Yes Shared CSP and CSC Customers retain ownership of their business data. GreenTriangle assigns service stewardship and operational ownership; contracts and DPAs define controller, processor and authorized-user responsibilities.
Data Security and Privacy Lifecycle Management Data Protection by Design and Default DSP-07.1 Are systems, products, and business practices based on security principles by design and per industry best practices? Yes CSP-owned Security by design is supported by threat and risk review, least privilege, tenant isolation, encryption, reviewed changes, automated testing, monitoring, backup and recovery.
Data Security and Privacy Lifecycle Management Data Privacy by Design and Default DSP-08.1 Are systems, products, and business practices based on privacy principles by design and according to industry best practices? Yes Shared CSP and CSC The service minimizes personal data, uses restrictive default access and allows customer administrators to assign roles. Processing follows documented purposes and applicable privacy law.
Data Security and Privacy Lifecycle Management Data Privacy by Design and Default DSP-08.2 Are systems’ privacy settings configured by default and according to all applicable laws and regulations? Yes Shared CSP and CSC The service minimizes personal data, uses restrictive default access and allows customer administrators to assign roles. Processing follows documented purposes and applicable privacy law.
Data Security and Privacy Lifecycle Management Sensitive Data Transfer DSP-10.1 Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope (as permitted by respective laws and regulations)? Yes Shared CSP and CSC Sensitive transfers use authenticated TLS channels and approved integrations. Authorization, customer scope and purpose limit each transfer; secrets and sensitive values are excluded from logs and evidence.
Data Security and Privacy Lifecycle Management Personal Data Access, Reversal, Rectification and Deletion DSP-11.1 Are processes, procedures, and technical measures defined, implemented, and evaluated to enable data subjects to request access to, modify, or delete personal data (per applicable laws and regulations)? Yes Shared CSP and CSC Data-subject requests are routed through the customer/controller or GreenTriangle privacy contact as appropriate. Search, correction, export and deletion actions are supported through controlled application and administrative procedures.
Data Security and Privacy Lifecycle Management Limitation of Purpose in Personal Data Processing DSP-12.1 Are processes, procedures, and technical measures defined, implemented, and evaluated to ensure personal data is processed (per applicable laws and regulations and for the purposes declared to the data subject)? Yes Shared CSP and CSC Personal data is processed only for documented service purposes, contractual delivery, support and applicable legal duties. Product design minimizes the personal data required.
Data Security and Privacy Lifecycle Management Personal Data Sub-processing DSP-13.1 Are processes, procedures, and technical measures defined, implemented, and evaluated for the transfer and sub-processing of personal data within the service supply chain (according to any applicable laws and regulations)? Yes Shared CSP and third party Subprocessing is governed through DPAs, an EU/EEA location and subprocessor register, access restrictions and supplier review. Material changes follow contractual notification requirements.
Data Security and Privacy Lifecycle Management Disclosure of Data Sub-processors DSP-14.1 Are processes, procedures, and technical measures defined, implemented, and evaluated to disclose details to the data owner of any personal or sensitive data access by sub-processors before processing initiation? Yes Shared CSP and CSC Customers receive the applicable subprocessor and location information before processing and are informed of material changes through the contractual process.
Data Security and Privacy Lifecycle Management Data Retention and Deletion DSP-16.1 Do data retention, archiving, and deletion practices follow business requirements, applicable laws, and regulations? Yes Shared CSP and CSC Retention and deletion follow contract, customer instruction, legal obligations and documented backup expiry. Exit procedures provide validated exports and controlled deletion after the agreed retention period.
Data Security and Privacy Lifecycle Management Sensitive Data Protection DSP-17.1 Are processes, procedures, and technical measures defined and implemented to protect sensitive data throughout its lifecycle? Yes CSP-owned Sensitive data is protected through minimization, role-based access, tenant isolation, encryption, restricted administration, audit, secure transfer, backup and controlled deletion.
Data Security and Privacy Lifecycle Management Data Location DSP-19.1 Are processes, procedures, and technical measures defined and implemented to specify and document physical data locations, including locales where data is processed or backed up? Yes Shared CSP and third party Production and backup locations are recorded in the service and subprocessor register. Core processing and storage remain in the EU/EEA, with current application, database and backup locations documented for customer review.
Governance, Risk and Compliance Governance Program Policy and Procedures GRC-01.1 Are information governance program policies and procedures sponsored by organizational leadership established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Controlled policies, evidence and metrics are maintained in the ISMS.
Governance, Risk and Compliance Governance Program Policy and Procedures GRC-01.2 Are the policies and procedures reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Controlled policies, evidence and metrics are maintained in the ISMS.
Governance, Risk and Compliance Risk Management Program GRC-02.1 Is there an established and maintained formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of risks? Yes CSP-owned A leadership-sponsored risk methodology and register define identification, likelihood, impact, ownership, treatment, residual-risk acceptance and review triggers.
Governance, Risk and Compliance Governance Responsibility Model GRC-06.1 Are roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs defined and documented? Yes CSP-owned The CEO/CTO is the ISMS and risk owner. Engineering, operations, privacy, service and control responsibilities are assigned through policies, operating procedures and delivery roles.
Governance, Risk and Compliance Information System Regulatory Mapping GRC-07.1 Are all relevant standards, regulations, legal/contractual, and statutory requirements applicable to your organization identified and documented? Yes CSP-owned Applicable legal, regulatory, privacy, contractual and customer-security requirements are recorded and reviewed at least annually and when entering a new jurisdiction or material contract.
Governance, Risk and Compliance Information System Regulatory Mapping GRC-07.2 Are the identified requirements reviewed at least annually or upon significant changes? Yes CSP-owned Applicable legal, regulatory, privacy, contractual and customer-security requirements are recorded and reviewed at least annually and when entering a new jurisdiction or material contract.
Human Resources Clean Desk Policy and Procedures HRS-03.1 Are policies and procedures requiring unattended workspaces to conceal confidential data established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Remote-working rules require private work areas, locked screens and protection of confidential information from household members, visitors and public view. The policy is reviewed annually and after material changes.
Human Resources Clean Desk Policy and Procedures HRS-03.2 Are policies and procedures requiring unattended workspaces to conceal confidential data reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Remote-working rules require private work areas, locked screens and protection of confidential information from household members, visitors and public view. The policy is reviewed annually and after material changes.
Human Resources Remote and Home Working Policy and Procedures HRS-04.1 Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Remote access requires approved endpoints, MFA, encrypted connections, VPN for administration, restricted company services and incident reporting. The baseline is reviewed annually and after material changes.
Human Resources Remote and Home Working Policy and Procedures HRS-04.2 Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Remote access requires approved endpoints, MFA, encrypted connections, VPN for administration, restricted company services and incident reporting. The baseline is reviewed annually and after material changes.
Human Resources Security Awareness Training HRS-11.1 Is a security awareness training program for all employees of the organization established, documented, approved, communicated, applied, evaluated and maintained? Yes CSP-owned All personnel receive continuous security awareness through onboarding, operational briefings and security findings. Engineers receive additional secure-development reinforcement through peer code review against documented review rules. Review outcomes, findings and incidents are used to update the programme.
Human Resources Security Awareness Training HRS-11.2 Are regular security awareness training updates provided? Yes CSP-owned Security updates are provided continuously through onboarding, peer code review, engineering security reviews, vulnerability notices and operational briefings. The ISO programme consolidates participation and effectiveness evidence.
Identity & Access Management Identity and Access Management Policy and Procedures IAM-01.1 Are identity and access management policies and procedures established, documented, approved, communicated, implemented, applied, evaluated, and maintained? Yes CSP-owned Identity and access procedures cover named accounts, MFA, role assignment, least privilege, provisioning, periodic review and prompt revocation. They are reviewed annually and after material changes.
Identity & Access Management Identity and Access Management Policy and Procedures IAM-01.2 Are identity and access management policies and procedures reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Identity and access procedures cover named accounts, MFA, role assignment, least privilege, provisioning, periodic review and prompt revocation. They are reviewed annually and after material changes.
Identity & Access Management Identity Inventory IAM-03.1 Is the inventory of identities managed, stored, and regularly reviewed, and is their level of access monitored? Yes CSP-owned Named workforce, service, customer and privileged identities and their access levels are recorded in the relevant identity, infrastructure and application systems and reviewed periodically.
Identity & Access Management Separation of Duties IAM-04.1 Is the separation of duties principle employed when implementing information system access? Yes CSP-owned Separation is applied between development, review, release and customer administration where practical. Small-team constraints use independent review, named approval and traceable records.
Identity & Access Management Least Privilege IAM-05.1 Is the least privilege principle employed when implementing information system access? Yes CSP-owned Keycloak roles, customer groups, database row-level security, scoped cloud roles and restricted administrative paths apply least privilege to application and infrastructure access.
Identity & Access Management Access Provisioning IAM-06.1 Is an identity access provisioning process defined and implemented which authorizes, records, and communicates data and assets access changes? Yes Shared CSP and CSC Access is requested or authorized by the responsible owner, assigned to a named identity, recorded in the relevant system and communicated to the user. Customer administrators control their nominated users and roles.
Identity & Access Management Access Changes and Revocation IAM-07.1 Is a process in place to de-provision or modify identity access in a timely manner? Yes Shared CSP and CSC Leaver and role-change procedures revoke sessions, credentials, VPN, repository, cloud and application access promptly. Customer administrators manage customer-user changes with supplier support where required.
Identity & Access Management Access Review IAM-08.1 Are reviews and revalidation of identity access for least privilege and separation of duties completed with a frequency commensurate with organizational risk tolerance, and at least annually or upon significant changes? Yes Shared CSP and CSC Privileged and workforce access is reviewed according to risk and at least annually; customer administrators review their own user population and role assignments.
Identity & Access Management Segregation of Privileged Access Roles IAM-09.1 Are processes, procedures, and technical measures for the segregation of privileged access roles defined, implemented, and evaluated? Yes CSP-owned Privileged access uses named accounts, separate infrastructure roles, VPN-restricted administration, MFA where supported and recorded changes. Application administration is separated from ordinary user roles.
Identity & Access Management Management of Privileged Access Roles IAM-10.1 Is an access process defined and implemented to ensure privileged access roles and rights are granted for a limited period? Yes CSP-owned The controlled process is operational. Standing privileged grants are limited to 12 months and require positive renewal; temporary grants expire when the task ends and normally within seven days. Reviews run quarterly, after role changes and immediately for leavers.
Identity & Access Management Management of Privileged Access Roles IAM-10.2 Are procedures implemented to prevent the accumulation of segregated privileged access? Yes CSP-owned Named accounts, least privilege, role separation and periodic access review prevent incompatible privileged rights from accumulating. Access is removed when responsibilities change.
Identity & Access Management Strong Authentication IAM-13.1 Are processes, procedures, and technical measures for authenticating access to systems, application, and data assets including multifactor authentication for a least-privileged user and sensitive data access defined, implemented, and evaluated? Yes Shared CSP and third party Keycloak provides OAuth 2.0/OIDC authentication, MFA and certificate-backed TLS. Workforce access to key services requires MFA, and service identities use certificates, signed tokens or protected credentials.
Identity & Access Management Strong Authentication IAM-13.2 Are digital certificates or alternatives that achieve an equivalent security level for system identities adopted? Yes Shared CSP and third party Keycloak provides OAuth 2.0/OIDC authentication, MFA and certificate-backed TLS. Workforce access to key services requires MFA, and service identities use certificates, signed tokens or protected credentials.
Interoperability & Portability Interoperability and Portability Policy and Procedures IPY-01.1 Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for communications between application interfaces (e.g., APIs)? Yes Shared CSP and CSC Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change.
Interoperability & Portability Interoperability and Portability Policy and Procedures IPY-01.2 Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information processing interoperability? Yes Shared CSP and CSC Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change.
Interoperability & Portability Interoperability and Portability Policy and Procedures IPY-01.3 Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for application development portability? Yes Shared CSP and CSC Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change.
Interoperability & Portability Interoperability and Portability Policy and Procedures IPY-01.4 Are policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained for information/data exchange, usage, portability, integrity, and persistence? Yes Shared CSP and CSC Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change.
Interoperability & Portability Interoperability and Portability Policy and Procedures IPY-01.5 Are interoperability and portability policies and procedures reviewed and updated at least annually, or upon significant changes? Yes Shared CSP and CSC Versioned external APIs, standard GIS services and documented open export formats support integration and portability. Interface and export procedures are reviewed annually and when material contracts or formats change.
Infrastructure Security Network Security I&S-03.1 Are communications between environments, services, and applications monitored? Yes CSP-owned Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually.
Infrastructure Security Network Security I&S-03.2 Are communications between environments, services, and applications encrypted? Yes CSP-owned Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually.
Infrastructure Security Network Security I&S-03.3 Are communications between environments, services, and applications restricted to only authenticated and authorized connections, as justified by the business? Yes CSP-owned Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually.
Infrastructure Security Network Security I&S-03.4 Are network configurations reviewed at least annually? Yes CSP-owned Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually.
Infrastructure Security Network Security I&S-03.5 Are network configurations supported by the documented justification of all allowed services, protocols, ports, and compensating controls? Yes CSP-owned Service and environment communications are monitored, encrypted and restricted by firewall, VPN, authentication and authorization. Allowed ports, protocols and service routes are documented and reviewed at least annually.
Infrastructure Security OS Hardening and Base Controls I&S-04.1 Is every host and guest OS, hypervisor, or infrastructure control plane hardened (according to their respective best practices) and supported by technical controls as part of a security baseline? Yes Shared CSP and third party Supported operating systems, minimal exposed services, default-deny host firewalls, automated security updates, container controls and provider hardening form the infrastructure baseline.
Infrastructure Security Segmentation and Segregation I&S-06.1 Are applications and infrastructures designed, developed, deployed, and configured such that service customer (tenant) access is appropriately segmented, segregated, monitored, and restricted? Yes CSP-owned Customer access is segmented through Keycloak groups and roles, tenant-aware APIs, database row-level security, object authorization and monitored administrative paths.
Infrastructure Security Migration to Cloud Environments I&S-07.1 Are secure and encrypted communication channels including only up-to-date and approved protocols used when migrating servers, services, applications, or data to cloud environments? Yes CSP-owned Server, service and data migrations use authenticated encrypted channels, approved protocols, controlled credentials and validation before cutover.
Infrastructure Security Network Defense I&S-09.1 Are processes, procedures, and defense-in-depth techniques defined, implemented, and evaluated for protection, detection, and timely response to network-based attacks? Yes Shared CSP and third party Defense in depth combines provider edge controls, default-deny firewalls, rate controls, CrowdSec threat detection and blocking, TLS, restricted administration, monitoring and incident procedures.
Logging and Monitoring Logging and Monitoring Policy and Procedures LOG-01.1 Are logging and monitoring policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Logging and monitoring policies cover application, infrastructure, authentication, administration, integrations, jobs, backups and security events. Coverage is reviewed annually and after material changes.
Logging and Monitoring Logging and Monitoring Policy and Procedures LOG-01.2 Are policies and procedures reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Logging and monitoring policies cover application, infrastructure, authentication, administration, integrations, jobs, backups and security events. Coverage is reviewed annually and after material changes.
Logging and Monitoring Audit Logs Access and Accountability LOG-04.1 Is audit log access restricted to authorized identities, and are records of that access maintained? Yes CSP-owned Operational and audit-log access is limited to authorized personnel and protected service roles. Administrative access and relevant log actions are recorded.
Logging and Monitoring Audit Logs Monitoring and Response LOG-05.1 Are capabilities implemented and maintained to correlate and monitor security audit logs for the detection of suspicious or anomalous activity that deviates from typical or expected patterns? Yes CSP-owned Central metrics and alerts cover availability, HTTP errors, capacity, backup age, replication, queues and jobs. CrowdSec analyzes security events and detected anomalies are reviewed and escalated.
Logging and Monitoring Audit Logs Monitoring and Response LOG-05.2 Is a process established and followed to review and take appropriate and timely actions on detected anomalies? Yes CSP-owned Central metrics and alerts cover availability, HTTP errors, capacity, backup age, replication, queues and jobs. CrowdSec analyzes security events and detected anomalies are reviewed and escalated.
Logging and Monitoring Audit Logs Sanitization LOG-08.1 Are technical measures defined, implemented, and evaluated to enable service customers to detect and scrub or tokenize sensitive data from logs, in order to prevent unauthorized exposure as per applicable laws and regulations? N/A CSP-owned Customers do not receive unrestricted raw infrastructure logs. GreenTriangle masks or excludes sensitive values before logging and provides customer audit records and exports containing only approved fields.
Security Incident Management, E-Discovery, & Cloud Forensics Incident Response Plans SEF-03.1 Is a security incident response plan that includes a communication strategy for notifying relevant internal departments, impacted service customers, and other business-critical relationships (such as supply-chain) established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned The incident process defines contacts, severity, containment, customer and supplier communication, legal assessment, recovery and follow-up. Customer notification follows applicable law, contract and incident impact.
Security Incident Management, E-Discovery, & Cloud Forensics Incident Response Testing SEF-04.1 Is a structured approach followed to evaluate the effectiveness of incident response plans at planned intervals or upon significant changes? Yes CSP-owned A structured exercise on 23 January 2025 tested response to PostgreSQL unavailability against the business continuity plan. It recorded the scenario, timeline, 2-hour-46-minute recovery, result against the four-hour objective, evidence limitations and assigned follow-up actions. Authenticated web and API security testing followed in August 2026.
Security Incident Management, E-Discovery, & Cloud Forensics Incident Management and Response SEF-07.1 Are processes, procedures, and technical measures defined, implemented, and evaluated for timely and effective response to security incidents in accordance with incident categories and severity levels? Yes CSP-owned Monitoring and incident contacts support severity-based triage, containment, recovery, customer communication and corrective action. Procedures are reviewed annually and after material incidents or changes.
Security Incident Management, E-Discovery, & Cloud Forensics Incident Management and Response SEF-07.2 Are these processes and procedures reviewed, updated, and tested at least annually? Yes CSP-owned Monitoring and incident contacts support severity-based triage, containment, recovery, customer communication and corrective action. Procedures are reviewed annually and after material incidents or changes.
Security Incident Management, E-Discovery, & Cloud Forensics Security Breach Notification SEF-08.1 Are processes, procedures, and technical measures for security breach notifications defined and implemented? Yes Shared CSP and third party Material incidents and relevant supplier incidents are assessed and reported under applicable GDPR, contractual and regulatory timelines, with affected customers receiving status and impact information.
Security Incident Management, E-Discovery, & Cloud Forensics Security Breach Notification SEF-08.2 Are material security breaches reported (including any relevant supply chain breaches) as per applicable SLAs, laws, and regulations? Yes Shared CSP and third party Material incidents and relevant supplier incidents are assessed and reported under applicable GDPR, contractual and regulatory timelines, with affected customers receiving status and impact information.
Supply Chain Management, Transparency, and Accountability Supply Chain Risk Management Policies and Procedures STA-01.1 Are policies and procedures for supply chain risk management established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Supply-chain governance records critical suppliers, service purpose, data access, location, assurance, contractual safeguards, owner and review. It is reviewed annually and after significant supplier changes.
Supply Chain Management, Transparency, and Accountability Supply Chain Risk Management Policies and Procedures STA-01.2 Are policies and procedures for supply chain risk management reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Supply-chain governance records critical suppliers, service purpose, data access, location, assurance, contractual safeguards, owner and review. It is reviewed annually and after significant supplier changes.
Supply Chain Management, Transparency, and Accountability SSRM Supply Chain STA-03.1 Is the SSRM applied, documented, implemented, and managed throughout the supply chain? Yes Shared CSP and third party The shared-responsibility model distinguishes GreenTriangle application and operational controls from hosting, storage, monitoring and other supplier controls while retaining supplier accountability.
Supply Chain Management, Transparency, and Accountability SSRM Control Ownership STA-05.1 Is the shared ownership and applicability of all CSA CCM controls delineated according to the SSRM? Yes Shared CSP and third party This CAIQ records whether GreenTriangle, the customer or a third party performs each control. Contracts, DPAs and service documentation assign customer and supplier duties.
Supply Chain Management, Transparency, and Accountability Supply Chain Inventory STA-08.1 Is an inventory of all supply chain relationships developed and maintained? Yes CSP-owned A controlled supplier and subprocessor inventory records each relationship, service, data access, processing location, assurance, contract owner and review status.
Threat & Vulnerability Management Malware and Malicious Instructions Protection Policy and Procedures TVM-02.1 Are policies and procedures to protect against malware and malicious instructions established, documented, approved, communicated, applied, evaluated, and maintained? Yes CSP-owned Endpoint platform protection, dependency controls, reviewed software, restricted server services and security updates protect against malware and malicious instructions. Policies are reviewed annually and after material changes.
Threat & Vulnerability Management Malware and Malicious Instructions Protection Policy and Procedures TVM-02.2 Are asset management and malware protection policies and procedures reviewed and updated at least annually, or upon significant changes? Yes CSP-owned Endpoint platform protection, dependency controls, reviewed software, restricted server services and security updates protect against malware and malicious instructions. Policies are reviewed annually and after material changes.
Threat & Vulnerability Management Vulnerability Identification TVM-03.1 Are processes, procedures, and technical measures defined, implemented, and evaluated for vulnerability detection on organizationally managed assets at least monthly? Yes CSP-owned Automated dependency and source checks run with code changes, supported by infrastructure review and periodic dynamic testing. Authenticated web and API testing in August 2026 reported no High-risk findings.
Threat & Vulnerability Management Detection Updates TVM-05.1 Are processes, procedures, and technical measures defined, implemented, and evaluated to update detection tools, threat signatures, and compromise indicators weekly (or more frequent) basis? Yes Shared CSP and third party Operating-system, CrowdSec, browser and endpoint protections use maintained threat intelligence and signatures. Dependency and vulnerability sources update continuously or with each scan.
Threat & Vulnerability Management Vulnerability Remediation Schedule TVM-08.1 Are processes, procedures and technical measures defined, implemented and evaluated based on identified risks to support scheduled and emergency responses to vulnerability identification? Yes CSP-owned Findings are prioritized using severity, exploitability, exposure and customer impact. Emergency releases support urgent containment and correction; every material correction is reviewed and retested.
Threat & Vulnerability Management Threat Response TVM-10.1 Is a risk-based method used for the prioritization and mitigation of threats, leveraging an industry-recognized framework to guide threat decision-making and protection measures? Yes CSP-owned Threat and vulnerability decisions use the ISMS risk method, OWASP guidance, CVSS where applicable and business-impact analysis.
Threat & Vulnerability Management Vulnerability Management Reporting TVM-11.1 Is a process defined and implemented to track and report vulnerability identification and remediation activities that include stakeholder notification? Yes CSP-owned Findings, owners, severity, correction, exceptions and retest evidence are tracked. The August 2026 authenticated testing and source and configuration review through an external security platform provider produced no High or Critical findings.
Universal Endpoint Management Application and Service Approval UEM-02.1 Is there a defined, documented, applicable and evaluated list containing approved services, applications, and the sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data? Yes CSP-owned The endpoint baseline restricts access to approved company services, applications and sources and prohibits unapproved software or browser extensions for company-data access.
Universal Endpoint Management Endpoint Inventory UEM-04.1 Is an inventory of all endpoints used and maintained to store, access and process company data? Yes CSP-owned Employee and approved contractor endpoints used for company access are inventoried with custodian, ownership, device identifier, operating-system version, access class and verification date.
Universal Endpoint Management Endpoint Management UEM-05.1 Are processes, procedures, and technical measures defined, implemented and evaluated, to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data? Yes CSP-owned Endpoint controls require supported macOS, security updates, FileVault, individual accounts, automatic locking, native malware protection, MFA, VPN administration and approved storage.
Universal Endpoint Management Automatic Lock Screen UEM-06.1 Are all relevant interactive-use endpoints configured to require an automatic lock screen? Yes CSP-owned Interactive endpoints require automatic screen locking after no more than ten minutes and a password-protected individual account.
Universal Endpoint Management Anti-Malware Detection and Prevention UEM-09.1 Are anti-malware detection and prevention technology services configured on managed endpoints? Yes CSP-owned Managed Mac endpoints retain Apple Gatekeeper and XProtect and receive supported operating-system and security updates.
Universal Endpoint Management Software Firewall UEM-10.1 Are software firewalls configured on managed endpoints? Yes CSP-owned Endpoint software firewalls are enabled as part of the device baseline, with network administration additionally restricted through the company VPN.
Universal Endpoint Management Remote Wipe UEM-13.1 Are processes, procedures, and technical measures defined, implemented, and evaluated to enable remote company data deletion on managed endpoint devices? Yes CSP-owned Apple Business Manager-backed device management enables centralized remote lock and wipe on managed company endpoints. Enrollment is being rolled out across the company device inventory; loss or offboarding also triggers immediate credential and session revocation.

Source framework: Cloud Security Alliance CCM-Lite and CAIQ-Lite v4.1.0.