Trust
An ERP holds the most sensitive data a company has, and a young vendor asking for it should be specific about its assurances rather than reassuring. This page states what we have, what is in progress, and what we do not have — the last of which is the part most vendors leave out.
SOC 2 report, DPA, sub-processor list, penetration test summary, and the correctness suite.
The six areas
Encryption in transit and at rest, MFA, role-based access, audit logging, backups with point-in-time recovery, and managed secrets.
SOC 2 Type I complete, Type II in progress. GDPR and CCPA handling, DPA available, sub-processors published.
A published property-based test suite over the accounting invariants, plus a third-party attest review of the engine. Separate from SOC 2, and the one most finance teams actually want.
Your data builds your corpus inside your tenant. It is not pooled across customers and not used to train shared models.
What happens if we cause a misstatement: detection, notification timeline, correction procedure, and who pays for remediation.
Uptime targets, incident history, status page, disaster recovery objectives, and how we communicate during an incident.
Stating this first, because a trust page that lists only achievements is a marketing page with a padlock on it.
SOC 2 assesses whether we run a controlled environment. It says nothing whatsoever about whether the ledger computes correctly. Those are different questions and they need different assurances, and a vendor answering the second by pointing at the first is either confused or hoping you are.
Our answer to the correctness question is threefold: a published property-based test suite over the accounting invariants, written to be readable by an accountant; a third-party attest firm engaged to review the engine and issue a written opinion; and the shadow ledger, which lets you verify against your own books daily rather than taking either of the first two on trust.
We will also join a call with your auditor without a salesperson present, which sounds minor and is the thing finance teams most often thank us for.
SOC 2 report under NDA, DPA, sub-processor list, penetration test summary, architecture overview, and the correctness suite. Most diligence questionnaires are answerable from it directly.
Questions
The pack answers most questionnaires directly, and we will join a call with your auditor without a salesperson present.