Third-party assurance
Northstar Cloud security review
Northstar meets the identity and encryption requirements. Its 72-hour incident notification commitment does not meet the internal 24-hour policy, so approval remains conditional on a contract amendment.
Northstar Cloud Platform Northstar Systems
2 satisfiedRequirements supported by evidence
1 policy gapIncident notice exceeds 24 hours
4 documentsVendor and internal evidence
Requirement matrix
Policy to evidence
Customer data is encrypted at rest using AES-256.
AES-256
Enterprise accounts can enforce SAML 2.0 single sign-on.
SAML 2.0
Northstar will notify customers within 72 hours of confirming a security incident.
2025-07-01/2026-06-30
Section 8.2, Security incident notice
Northstar will notify customers within 72 hours of confirming a security incident.
4
Notify customers within 24 hours
The vendor commitment exceeds the policy maximum by 48 hours.
Satisfied
Policy gap
Approval decision
Procurement disposition
Proceed only after the data processing addendum changes incident notification from 72 hours to 24 hours.
Pending review Conditional approval ApprovedPublished SHACL contract
Machine-checkable completeness
Requirements publish one status, decisions select one option, and notification limits use typed durations.
- Every requirement must have exactly one review status.
- Every approval decision must select exactly one option.
- Every notification limit must be one day-time duration.