← Trust CenterTrust · Vendor Assessment
Security Questionnaire (CAIQ-Lite)
Pre-answered responses to accelerate your procurement review. Enterprise plans receive the full CAIQ v4 and SIG Lite on request.
Governance
Do you have an information security program?
Yes. Policies cover access control, incident response, change management, vendor management, and business continuity. Reviewed annually.
Do you have a named security lead?
Yes. security@sellexio.co is monitored by the CTO.
Architecture
Where is customer data stored?
Primary storage in Supabase (AWS us-east-1). Enterprise plans can be pinned to eu-west-1. Files in encrypted object storage.
Is customer data logically or physically separated?
Logically, via row-level security keyed on org_id. Every table enforces org isolation before any read or write.
Access
How is administrative access controlled?
Role-based (viewer / analyst / comptroller / admin). Roles live in a separate table with SECURITY DEFINER lookup. TOTP MFA required for admin and comptroller.
Do you support SSO?
Yes. SAML 2.0 SSO on Enterprise plans via /settings/sso. Domain-scoped IdP registration.
Do you support SCIM provisioning?
On roadmap for Q1 2027. Manual invite + role assignment available today.
Encryption
Encryption in transit?
TLS 1.2+ enforced on all endpoints. HSTS enabled on the marketing and app domains.
Encryption at rest?
AES-256 across primary database, backups, and object storage.
Key management?
Managed by the underlying cloud provider (AWS KMS via Supabase). No customer-managed keys today.
Logging
What is logged?
Auth events, role grants, claim state transitions, document uploads, AI calls (prompt hash, tokens, latency, model).
Can logs be exported?
Yes, Enterprise plans can register a signed webhook at /settings/enterprise to receive audit events in real time.
Incident
Breach notification SLA?
Notification to affected customers within 72 hours of confirmation, per GDPR Art. 33.
Runbook tested?
Tabletop drill quarterly. Documented in the internal incident-response runbook.
Vulnerabilities
Do you run dependency scans?
Yes, automated on every deploy. High/critical findings block deploy.
Third-party pen test?
Scheduled Q3 2026 with Cure53. Executive summary available under NDA on request.
AI
Do AI providers train on customer data?
No. OpenAI is called on zero-retention business endpoints. Gemini is used via a gateway that does not enable model training. Every AI call is logged.
Are AI outputs binding?
No. All AI outputs are advisory and marked as such in the UI. A human comptroller must approve any claim before it moves past draft.
BC/DR
RTO / RPO?
RTO 4 hours, RPO 15 minutes for the primary database. Point-in-time recovery covers 7 days.
Backup testing?
Restore verified monthly against a clean environment.
Compliance
SOC 2?
SOC 2 Type I targeting Q4 2026 with Vanta. Interim SOC 2-in-progress letter available on request.
GDPR / UK GDPR?
DPA with SCC Module 2 and the UK IDTA available at /legal/dpa. Signable in-app.
Insurance
Do you carry E&O / cyber insurance?
USD 2M each in binding at time of publication; certificates available on request.