Skip to main content
DREXUS
ZRH · 07:26Request Proposal
§ PROCUREMENT · 00   Security & vendor evaluation packDOCS 6RESPONSE <24HREGION CH · EU · USHomeProcurementFILED ·

Procurement, without
the friction.

Everything your security and procurement teams need — checklist, policies, certifications, templates. We answer detailed questionnaires within 48 hours and sign mutual NDAs before deep-dives.

Browse documents
§ 02 — Security checklist

Compliant by default.

§ DATA PROTECTION4 ITEMS

Encryption at rest

AES-256 encryption for all stored data

✓ COMPLIANT

Encryption in transit

TLS 1.3 for all API communications

✓ COMPLIANT

Data residency controls

Client-specified region deployment available

✓ COMPLIANT

Right to deletion

Complete data purge within 30 days of request

✓ COMPLIANT
§ ACCESS CONTROL4 ITEMS

Multi-factor authentication

Mandatory 2FA for all team members

✓ COMPLIANT

Role-based access control

Principle of least privilege enforced

✓ COMPLIANT

Access logs and audit trails

90-day retention of all access logs

✓ COMPLIANT

Background checks

All team members undergo verification

✓ COMPLIANT
§ DEVELOPMENT SECURITY4 ITEMS

Secure SDLC

Security integrated at every phase

✓ COMPLIANT

Code reviews

Mandatory peer review for all changes

✓ COMPLIANT

Dependency scanning

Automated vulnerability scanning

✓ COMPLIANT

Security testing

SAST/DAST in CI/CD pipeline

✓ COMPLIANT
§ COMPLIANCE4 ITEMS

SOC 2 Type II

Audit scheduled Q2 2024

◐ IN PROGRESS

GDPR compliance

Full compliance with EU regulations

✓ COMPLIANT

CCPA compliance

California privacy rights supported

✓ COMPLIANT

HIPAA capability

BAA available for healthcare clients

✓ COMPLIANT
§ 03 — Key policies

Read the fine print.

§ 04 — Certifications & audits

Audited, twice over.

§ CURRENT

  • ISO 27001:2013 (Information Security)
  • GDPR Compliant
  • CCPA Compliant

§ IN PROGRESS

  • SOC 2 Type II (Q2 2024)
  • ISO 9001:2015 (Q3 2024)
EVALUATE · WITH · CONFIDENCE

Drop us a questionnaire.

Send your security questionnaire (CAIQ, SIG, custom). We respond within 48 hours with documented evidence and references.

Email procurement
FILED · · DREXUS® TOOLBOX · PRC
§ 07 — Subscribe

Strategic insights, weekly.

One actionable insight every Tuesday — no fluff, no sales pitches. Strategies from our work with 100+ companies, distilled to a single page.

JOIN 8,000+ TECHNOLOGY LEADERS · UNSUBSCRIBE ANYTIME