Onboarding Platform Security Compliance Questionnaire Form
Use this form to share your organization’s security and compliance readiness for platform onboarding.
Organization Details
Organization Name
*
Primary Contact Name
*
Work Email Address
*
example@example.com
Role / Title
Security Compliance Profile
Organization type / industry
*
Please Select
Technology
Healthcare
Financial Services
Education
Retail
Manufacturing
Government
Nonprofit
Other
Approximate employee count
*
Please Select
1–10
11–50
51–200
201–500
501–1,000
1,001–5,000
5,001+
Does the organization have an internal security team?
*
Yes
No
Security Program Overview
Security program maturity/status
Please Select
Initial
Developing
Defined
Managed
Optimized
Other
Brief description of the platform or environment being onboarded
*
Policy and Control Coverage
Which policies or controls are currently in place?
*
Access control
Password policy and multi-factor authentication
Incident response
Data retention
Vendor risk management
Change management
Other
Which access control measures are implemented?
Role-based access control
Least privilege access
Privileged access reviews
Periodic access reviews
Segregation of duties
Other
Other relevant controls
Technical Security Practices
Authentication methods used
*
Single sign-on (SSO)
Multi-factor authentication (MFA)
Biometric authentication
One-time passcodes (OTP)
Hardware security keys
Other
Is multi-factor authentication enforced for administrators?
*
Yes
No
Encryption in use
*
Data at rest
Data in transit
Both
Not currently used
Other
Compliance and Audit Readiness
Applicable frameworks or attestations
*
SOC 2
ISO 27001
PCI DSS
NIST CSF
CSA STAR
None
Other
Recent security review or audit completed
*
Yes
No
In progress
Planned
Date of most recent review
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Incident Response and Reporting
Does your organization have a documented incident response plan?
*
Yes
No
In Progress
Other
Primary security incident reporting email
example@example.com
Target notification timeframe after incident detection
*
Please Select
Immediate (within 1 hour)
Within 4 hours
Within 24 hours
Within 72 hours
Other
Data Handling and Subprocessors
What types of data will the platform process or store?
*
Personal Data
Sensitive Personal Data
Financial Data
Health Data
Authentication Data
Usage Analytics
Other
Do you use any subprocessors or third-party services?
*
No
Yes
Name of critical subprocessors (if applicable)
Additional Notes and Follow-Up
Additional security or compliance notes
Preferred follow-up method and time window
Please Select
Email during business hours
Phone during business hours
Email in the morning
Phone in the afternoon
Either email or phone
Other
Submit
Should be Empty: