VentaHR
RFP Ready

Security RFP Answers

Copy-paste ready answers for your security questionnaires

Governance

Does your organization have a formal information security program?

Yes. We maintain an information security program with documented policies, procedures, and controls aligned with SOC 2 Type II framework principles. This includes regular risk assessments, security training, and continuous monitoring.

Is a security officer or team designated?

Yes. A dedicated security function oversees the information security program, including policy development, incident response, and compliance monitoring.

Are security policies reviewed and updated regularly?

Yes. Security policies are reviewed at least annually and updated as needed based on risk assessments, regulatory changes, and industry best practices.

Access Controls

What authentication mechanisms are supported?

Email/password authentication with multi-factor authentication (MFA) support. SSO/SAML integration available for enterprise customers. Password complexity and session timeout policies enforced.

How is role-based access control (RBAC) implemented?

Granular RBAC with platform-level and tenant-level roles. Principle of least privilege enforced. Permissions are reviewed regularly and adjusted based on job function changes.

How are privileged accounts managed?

Privileged access is restricted to authorized personnel only. Administrative actions are logged. Periodic access reviews are conducted to ensure appropriate access levels.

What is the user provisioning and de-provisioning process?

User access is provisioned based on approved requests. De-provisioning occurs immediately upon termination or role change. Automated processes ensure timely removal of access rights.

Data Protection

What encryption standards are used for data at rest and in transit?

Data at rest: AES-256 encryption. Data in transit: TLS 1.2 or higher. Encryption keys are managed using industry-standard key management practices with appropriate rotation policies.

How is tenant data isolation achieved?

Logical separation at application and database layers. Tenant identifiers validated on every request. Cross-tenant data access prevented through access control policies and query filters.

Where is customer data stored?

Customer data is hosted on enterprise-grade cloud infrastructure with geographic redundancy. Specific regions are documented in service agreements and can be configured based on customer requirements.

Is customer data used for purposes other than service delivery?

No. Customer data is not used for AI training, marketing analytics, or shared with third parties without explicit customer consent. Data is processed solely for service delivery purposes.

Secure Development Lifecycle

Is secure coding training provided to developers?

Yes. Development team receives security training including OWASP Top 10, secure coding practices, and threat modeling. Training is refreshed annually.

What testing is performed before production deployment?

Code review, automated security scanning, dependency vulnerability checks, and functional testing. Critical changes undergo additional review by senior engineers.

How are security vulnerabilities in dependencies managed?

Continuous dependency monitoring with automated alerts for known vulnerabilities. Security patches prioritized based on severity and exploitability. Critical patches expedited.

Is a vulnerability disclosure program available?

Yes. Security researchers and customers can report vulnerabilities to our security team. Reports are triaged and remediated based on severity.

Monitoring & Logging

What events are logged?

User authentication events, administrative actions, data access, configuration changes, failed login attempts, and security-relevant system events. Logs include timestamp, actor, action, and affected resources.

How long are logs retained?

Minimum 90 days with extended retention available for compliance requirements. Audit logs are immutable and tamper-evident.

Is real-time alerting configured?

Yes. Automated alerting for security events including unauthorized access attempts, configuration changes, and system anomalies. Security team receives and triages alerts 24/7.

Can customers access their audit logs?

Yes. Customers can access audit logs relevant to their tenant through the platform's audit interface or via export functionality.

Business Continuity & Disaster Recovery

What is the backup strategy?

Automated daily backups with point-in-time recovery. Backups encrypted and stored in geographically separate locations. Backup integrity verified through periodic restore tests.

What are the Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?

Target RTO: <4 hours. Target RPO: <24 hours. Actual performance may vary based on incident scope and complexity. Recovery procedures are documented and tested.

Is disaster recovery testing performed?

Yes. Disaster recovery procedures are tested periodically. Results inform updates to recovery playbooks and infrastructure improvements.

What is the uptime commitment?

Target availability is documented in service level agreements. System status and incident history are available to customers through status pages.

Privacy & Data Handling

Who owns customer data?

Customers retain full ownership of their data. We act as a data processor on behalf of customers (data controllers) per applicable data protection regulations.

Are Data Processing Agreements (DPAs) available?

Yes. DPAs, Business Associate Agreements (BAAs), and Standard Contractual Clauses (SCCs) are available based on customer requirements. Contact your account team.

What data minimization practices are implemented?

Only data necessary for service delivery is collected. Configurable retention policies allow customers to define data lifecycle. Data deletion requests honored per contractual terms.

How are data subject access requests (DSARs) handled?

Customers can export their data directly through the platform. We provide assistance with DSARs as required by applicable data protection laws.

Subprocessors

What third-party vendors (subprocessors) process customer data?

Current subprocessor list is available at /security/subprocessors. All subprocessors are vetted for security and data protection practices.

How are subprocessors managed?

Third-party risk assessments conducted prior to engagement. Data processing agreements in place with all subprocessors. Periodic reviews ensure ongoing compliance.

Are customers notified of new subprocessors?

Yes. Customers are notified of material changes to subprocessor lists per contractual terms. Objection mechanisms are provided where applicable.

Customer Responsibilities

What is the shared responsibility model?

We are responsible for security OF the platform (infrastructure, application, access controls). Customers are responsible for security IN the platform (user access management, data classification, appropriate use).

What security practices are expected of customers?

Strong password practices, enabling MFA, timely user de-provisioning, regular access reviews, appropriate data classification, and adherence to acceptable use policies.

Need Customized Responses?

Contact us for tailored security documentation and questionnaire assistance