Current
Trust operations Vendor review
MC

Third-party assurance

Northstar Cloud security review

Conditional approval

Northstar meets the identity and encryption requirements. Its 72-hour incident notification commitment does not meet the internal 24-hour policy, so approval remains conditional on a contract amendment.

2 satisfiedRequirements supported by evidence 1 policy gapIncident notice exceeds 24 hours 4 documentsVendor and internal evidence

Requirement matrix

Policy to evidence

3 requirements
Data protection Encrypt customer data at restProduction and backup storage Satisfied
Access control Support SAML single sign-onEnforce centralized workforce access Satisfied
Incident response Notify within 24 hoursVendor commitment is currently 72 hours Policy gap

Approval decision

Procurement disposition

Live decision

Proceed only after the data processing addendum changes incident notification from 72 hours to 24 hours.

Reviewed by Maya Chen

Published SHACL contract

Machine-checkable completeness

3 shapes

Requirements publish one status, decisions select one option, and notification limits use typed durations.

  • Every requirement must have exactly one review status.
  • Every approval decision must select exactly one option.
  • Every notification limit must be one day-time duration.