11 questions in this section
partialDoes the Applicant collect, store, process, transmit PII / PHI / PCI?
attestedDoes the Applicant collect biometric information (fingerprints, voice, face, iris, etc.)?
attestedIs the Applicant PCI-DSS compliant, and at what merchant level?
attestedHas the Applicant confirmed HIPAA compliance?
verifiedIs sensitive data encrypted in transit?
partialIs the Applicant compliant with cross-border data transfer laws?
attestedDoes the Applicant have written information security policy reviewed and updated annually?
partialAre users able to store data to the hard drive of portable computers or portable media devices?
verifiedDoes the Applicant employ Data Loss Prevention (DLP)?
attestedDoes the Applicant have written privacy policy reviewed by attorney and updated annually?
partialDo users store business-critical information locally on their systems rather than on centralized storage?
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture