Is customer data encrypted in transit?
YesAll traffic to the application and between the application and its database uses TLS 1.2 or better. Plain HTTP requests are redirected and HSTS is set. Verified during this review.
This is a sample. Northwind Labs isn't a real company, the customer asking isn't real, and none of this describes a real client. I wrote it to show exactly what you get, down to the wording.
A three-person company answering a 94-question vendor security review from an enterprise customer. Twelve of the answers are shown here, including all three we answered no to.
Every yes in this document is true, because I either checked it or fixed it first. That is the whole method, and it is the only thing that makes the rest of the answers worth anything.
Three answers are no. A no with a reason and a plan does not lose deals. Security teams read these for a living and they can tell when a small company has ticked yes to a control it does not operate. That is what loses deals, usually six months later when someone asks for evidence.
Where a control did not exist and could be put in place in days, I put it in place and the answer says so. Where it could not, the answer says what happens instead. Nine of the twelve answers below were made true during the work; four of them had to be built first.
This goes out with the questionnaire, and again to the next customer who asks before they send a spreadsheet of their own. It is the single most reused thing I produce.
Northwind Labs — security summary
March 2026
Shown as they were submitted. Where something had to be built or changed to make an answer true, the answer says what changed and when.
All traffic to the application and between the application and its database uses TLS 1.2 or better. Plain HTTP requests are redirected and HSTS is set. Verified during this review.
The managed Postgres instance and its backups are encrypted at rest by the provider (AWS eu-west-2). Uploaded files are stored encrypted in the same region.
Both accounts able to reach customer data require a hardware security key. There are no shared logins and no accounts exempt from the requirement.
It was on for the application but not for the hosting account or the domain registrar, which is where it matters most. Both were enforced on 3 March 2026, and a third dormant administrator account was removed.
Northwind is three people and neither is realistic this year. Rather than promise one, here is what we offer in its place: this questionnaire answered honestly and in full, an independent security review dated March 2026 by a named engineer, the one-page summary attached, and a named person who will answer any follow-up question directly. If certification is a hard requirement for your organisation, we would rather know now than at contract stage.
Not a penetration test, and we will not call one something it is not. What we have is an independent security review completed in March 2026: source code, configuration, database rules and the running application tested as an authenticated user and as an unauthenticated stranger. The difference is that a penetration test is adversarial and time-boxed against a live target, usually by a team. If you require a penetration test specifically, we will commission one; we would ask for your scope requirements so it answers your question rather than ours.
There are three of us and two founders hold all access. There are no employees to check. If Northwind hires someone with access to customer data, checks will start at that point, and we will tell you. We would rather answer this no than tick a box for a process we do not operate.
One page: who is called, what is checked first, who is told and when, and who speaks to customers. It commits us to telling an affected customer within 24 hours of confirming an incident, before the full extent is known. Attached as appendix B.
It did not exist. It was written on 4 March 2026 and walked through once against a worked scenario.
Nightly, retained 35 days, encrypted, held by the database provider. A restoration test is now run quarterly, timed and recorded.
Backups had run nightly for two years and had never once been restored. We restored one to an isolated database on 4 March 2026: it took 22 minutes and was complete. Until that test, the honest answer to this question would have been no.
Administrative actions are written to an append-only log recording who, what, which record and when, retained for 400 days.
Added on 5 March 2026. Activity before that date is not logged, and we would tell you that rather than let you assume otherwise.
Four. AWS (eu-west-2): all application and customer data, hosting. Stripe (EU/US): billing contact and payment details, no product data. Postmark (EU): email addresses and message content for transactional email. Sentry (EU): error reports, with user identifiers stripped. The list is maintained at northwindlabs.example/subprocessors and we give 30 days' notice before adding one.
Export as CSV or JSON within 5 working days of a request. Deletion from the live system within 30 days. One nuance worth stating rather than hiding: deleted data persists in encrypted backups until those backups age out, which is up to 35 days after deletion. Nothing restores from them selectively, and the backups are not accessible to the product.
[email protected], reaching a person, published on the website and in a security.txt file at the standard location. We answer within two working days.
There was no published contact before 5 March 2026. A researcher who found something had no way to tell us except the general support address.
Nate Parker
App Locksmith, applocksmith.com
Completed 6 March 2026. I join the call if the customer's security team wants to go through any answer.
I check your app against every question, fix what would fail, and write the answers with you. Every yes is true, and the ones that have to be no come with a reason and a plan.