Demonstration only

Fictional ExampleCo evidence pack

This is not a real company. Every organization, control, evidence description, result, and gap below is fictional. Nothing here is a testimonial, customer claim, certification, or security assessment.

The sample demonstrates the delivery format and the discipline of separating verified facts, partial evidence, gaps, and non-applicable questions.

Artifact 1

Answer bank

Positive claims require evidence references. A partial answer preserves its limitation rather than silently upgrading it.

ControlDomainQuestionSafe answerStatusEvidence
SEC-001Access controlIs multifactor authentication required for production administrative access?Fictional ExampleCo requires SSO and multifactor authentication for production administrative roles.VERIFIEDEV-001
SEC-002Access controlHow often are privileged access rights reviewed?Fictional ExampleCo has a written quarterly review target but supplied evidence confirms only one review in the last year.PARTIALEV-002;EV-003
SEC-003Data protectionIs customer data encrypted in transit?Fictional ExampleCo's public application endpoint enforces modern TLS through its fictional managed hosting provider; internal service paths were not evidenced.PARTIALEV-004
SEC-004Data protectionIs customer data encrypted at rest?The supplied fictional provider configuration states managed database storage encryption is enabled for the production database.VERIFIEDEV-005
SEC-005Incident responseHas the incident response plan been tested in the last 12 months?No completed exercise record was supplied; Fictional ExampleCo cannot currently claim the plan was tested.GAP
SEC-006ResilienceAre backups restored in a recurring test?Backups are configured but no successful restoration record was supplied.PARTIALEV-006
SEC-007Application securityAre code changes independently reviewed before production?The fictional protected-branch configuration requires one approving review for the production branch.VERIFIEDEV-007
SEC-008Vulnerability managementDoes the company have a documented vulnerability disclosure channel?No public security contact or disclosure policy was supplied.GAP
SEC-009SubprocessorsIs a current list of subprocessors available to customers?Fictional ExampleCo maintains a dated customer-facing subprocessor list covering the providers in the supplied architecture note.VERIFIEDEV-008;EV-009
SEC-010AI governanceIs customer content used to train third-party models?The supplied fictional model-provider agreement states API inputs are not used for model training by default; Fictional ExampleCo must separately confirm it does not opt in or reuse content itself.PARTIALEV-010
SEC-011Physical securityDoes the vendor operate its own data center?Fictional ExampleCo does not operate a data center; its application uses a managed cloud provider. Provider physical controls are addressed through the provider's assurance material.NOT APPLICABLEEV-009
SEC-012AssuranceIs Fictional ExampleCo SOC 2 certified?No. Fictional ExampleCo has not supplied a SOC 2 report and must not claim certification.GAP

Artifact 2

Evidence index

The pack records evidence metadata and customer-approved references. This public sample contains descriptions only—never real artifacts.

IDEvidence descriptionScopeEffective dateClassification
EV-001Fictional identity-provider administrative policy exportProduction admin group2026-07-15CONFIDENTIAL METADATA ONLY
EV-002Fictional access review policyAll workforce access2026-01-10INTERNAL
EV-003Fictional completed access review recordProduction roles2025-11-30CONFIDENTIAL METADATA ONLY
EV-004Fictional managed-host TLS configuration exportPublic application endpoint2026-07-20INTERNAL
EV-005Fictional database encryption settings exportProduction managed database2026-07-20CONFIDENTIAL METADATA ONLY
EV-006Fictional backup settings exportProduction managed database2026-07-20INTERNAL
EV-007Fictional protected-branch settings exportProduction branch2026-07-18INTERNAL
EV-008Fictional subprocessor listCustomer-facing providers2026-07-01PUBLIC
EV-009Fictional architecture and data-flow noteProduction SaaS2026-07-01CONFIDENTIAL METADATA ONLY
EV-010Fictional model-provider data-use terms excerptAPI service default terms2026-06-01PUBLIC

Artifact 3

Gap register

A useful gap record states what is missing, why it matters, what can safely be said now, and the next owner-controlled action.

GAP-001 · High priority

No completed tabletop/exercise record

Safe current answer
Plan exists; no completed test evidence supplied.
Next action
Schedule a scoped exercise and retain date, participants, scenario, findings, and follow-up evidence.

GAP-002 · High priority

Backups configured but restoration not evidenced

Safe current answer
Backups are configured; recurring restore testing is not yet evidenced.
Next action
Run an authorized non-production restoration and record success criteria/results.

GAP-003 · Medium priority

No public disclosure channel

Safe current answer
No formal public VDP is currently published.
Next action
Draft security contact, scope, safe-harbor language, triage owner, and response targets; obtain appropriate review before publishing.

GAP-004 · Medium priority

Quarterly target not consistently evidenced

Safe current answer
Policy calls for quarterly review; one annual record was supplied.
Next action
Complete review and add a recurring owner-controlled reminder.

Need this structure for a real buyer review?

The pilot uses only customer-authorized source material and leaves unsupported claims visible.

Check pilot fit