Security packet
Enterprise questionnaires and NDA diligence get a fixed packet — not a slide
deck. Operators build the zip from the private monorepo with
scripts/build_security_packet.py. Prospects receive it under NDA on request.
What’s in the packet
| Document | Answers |
|---|---|
| DPA template | Processing roles, sub-processors, international transfers |
| Data retention | What we store, for how long, deletion |
| Subprocessors | AWS, WorkOS, Bedrock/Anthropic, GitHub — annual review expected |
| Shared responsibility | Hosted vs self-host split |
| Incident response | Severity, notification, owner slots |
| Reference architecture | Control-plane topology (API, gateway, console, evidence) |
| Secure SDLC | PR gates, CI, release checksums / SBOM |
| Access control / Infosec / Vendor management | Org policy templates for SOC 2 onboarding |
| Determinism | Why enforcement never depends on an LLM |
| Enterprise questionnaire | Standard security Q&A seed answers |
| Continuity & recovery | Backup / rebuild posture |
How to request it
Email your Unveilr contact (or security@unveilr.ai when published) with your
company legal entity and NDA status. Turnaround target: within 24 hours.
Related public pages
- Trust Center — verifiable claims and SOC 2 status
- Prove — in-product evidence and framework packs
- Self-hosting — deploy in your VPC