For procurement and InfoSec teams

Procurement collateral pack

Most enterprise procurement reviews ask the same three things up front: a DPA, a security overview, and where we are on SOC 2. Here they are — preview in your browser or download. For a counter-signed customer-form DPA, NDA, or vendor security questionnaire, contact support@sentinelcmt.com.

Vendor Due Diligence Summary (one-pager)

Start here. One-page consolidator for corporate IT, finance, and procurement reviewers. Business identity (ABN, address, founder), independent trust signals (G2 listing, Microsoft Cloud Partner ID, LinkedIn), pricing & purchasing terms, and a security posture summary with pointers to the deeper packs below.

Data Processing Agreement (DPA)

Short-form, GDPR Art. 28 / Australian Privacy Principles-aligned DPA. Lists categories of data, sub-processors, breach-notification commitments, deletion at termination.

Security Overview (one-pager)

Quick-reference one-pager covering architecture, identity & access, encryption (TLS / Fernet at rest), audit logging, rate limiting, and incident response. Use this for your first procurement read-through.

Security Brief (detailed)

Comprehensive, board-presentable security statement: PII redaction flow before LLM transmission, model-provider commitments, encryption at rest and in transit, audit logging, data retention by class, and honest disclosure of controls not yet in place. Use this when your CISO or Internal Audit team asks for depth.

SOC 2 Roadmap

Honest statement of where Sentinel is on the SOC 2 journey — controls already in place, acknowledged gaps, and timeline to Type I and Type II.

Need something we don't list?

Vendor security questionnaires, supplemental insurance evidence, or a counter- signed copy of your customer-form DPA — email support@sentinelcmt.com and we'll turn it around inside a business day.

Output usability

Sentinel applies a content-type-aware Usability Mapping discipline to every generated artefact, aligned to AS ISO 24495-1:2024 (Australian Plain Language Standard). Strategic content (manual sections, Standards Review, executive summaries) is pitched at senior-professional register (Flesch-Kincaid Grade 11-13). Operational content read mid-exercise (scenario injects, TARP rows, Duty Cards, holding statements) is pitched at cognitive-load-aware Grade 9-10 — short active sentences, imperative verbs, concrete nouns, scannable structure. This mirrors the discipline applied to aviation Quick Reference Handbooks and military Rules of Engagement: readers are degree-qualified professionals, but the content is shaped for how it is consumed, not the reader's IQ. Full detail in the Security Brief.

Made with Emergent