Separate controls from assurance.
Give security and procurement teams a concrete review path: inspect source-backed controls and request the evidence needed for their decision.
What can be answered from source
These statements describe the reviewed implementation. They are not an independent assessment of the deployed service. Scope the questionnaire to the selected integration and ask for operational evidence where source alone cannot answer.
| Question | Source-informed answer | Additional evidence |
|---|---|---|
| Who authorizes requests? | Verified application identity and current membership/operation checks. | Target session policy, provisioning, revocation and MFA/SSO decision. |
| How is tenant scope applied? | Organization and own-record restrictions in selected domain flows. | Independent cross-tenant tests on deployed schema/configuration. |
| Can a browser confirm a payment? | Authoritative verified evidence is required; browser return is insufficient. | Approved provider protocol and adverse-event walkthrough. |
| Does public documentation expose records? | Static authored allowlist; no internal-file or customer-data reader. | Published-route/asset and deployment review. |
| Are secrets and encryption operations audited? | Public docs contain no credentials. This pack does not verify live key custody or rotation. | Restricted key-management, transport, storage and rotation evidence. |
| Independent assurance available? | No SOC 2, ISO certification, PCI attestation or penetration-test report is established here. | Dated report, scope, issuer and remediation status where available. |
A restricted review has a separate boundary.
Public material can explain control design and evaluation gates. A named security team may request sanitized architecture detail, assessment summaries, subprocessor evidence, restore results and remediation tracking under agreed confidentiality and sharing terms. Credentials, raw customer data and unrestricted infrastructure access are not assessment deliverables.
Close findings before expanding access.
Record each finding’s affected operation, impact, owner, due date, remediation evidence and authorized decision. Obtain current independent review for material authorization or financial changes. This public guide supplies no vulnerability bounty, guaranteed response clock or assurance that no vulnerabilities exist.