For the CIO and IT

“Another vendor holding our deal data.”

Fair. Here is what you would be approving, stated the way you will have to restate it internally. Every line is evidenced on the Trust page rather than asserted here.

Separation
Row-Level Security on every table, enforced in the database rather than in application code. One tenant cannot read another's rows even when the application is wrong.
Encryption
AES-256 at rest and TLS 1.2+ in transit, with AWS KMS envelope encryption for the tokens that connect to your other systems.
Identity
OIDC and SAML single sign-on, multi-factor authentication mandatory, and FIDO2 passkeys. Your directory stays the source of truth for who exists and who left.
Audit
An audit log across every API route, with read-only viewer and audit roles so an internal reviewer never needs write access to check something.
AI and your data
Inference runs through AWS Bedrock inside the AWS environment. No model training is performed on customer data, and an AI suggestion never changes a record without a person accepting it.
Exit
Data is retained only while the account is active and is available for export after termination. Erasure covers derived records, not only the primary row.
Assurance
SOC 2 Type II is in its observation period to 18 November 2026 — not yet certified. ISO 27001 sits at 118 of 118 controls with the audit under way, and an independent penetration test found no critical, high or medium issues.

Take this to your review

The vendor evaluation checklist restates all of it as a grid you can paste into your own template, and prints to a single page.

Vendor evaluation checklist