Trust center // audit portal Operational

Everything your security team needs to say yes.

Standardized vendor security packs, a structured incident notification protocol and a zero sub-processor declaration, in one place. Read any document right here. Request the completed pack for your account in under a minute.

Browse documents
SolerWorksSECURITY PACKVendor Security PackSIG LITECAIQYOUR REGULATORY WINDOW72 hoursEVENTREPORTNOTICE72HSUB-PROCESSORSZero sub-processorsEngineers contracted by SolerWorks

Compliance artifact directory

The documents reviewers ask for, ready before they ask

Filter by reviewer, read any document right here, or download it as PDF or Word. Completed versions for your account ship in the audit dossier.

Standardized Vendor Security Pack

Standard responses across eight control domains, every answer linked to evidence. Written to answer what a SIG Lite or CAIQ review asks, ready for your vendor risk workflow.

SIG LiteCAIQSecurity · vendor riskDOCXUpdated 20 Sep 2026
Preview structure

Control domains

  1. Organization and governance
  2. Access control
  3. Devices and endpoints
  4. Data handling
  5. Personnel
  6. Incident response
  7. Sub-processors
  8. Business continuity

How it reads

Each line carries a question, the answer and the supporting evidence. The completed pack is tailored to your account and delivered in the audit dossier.

Record of Processing Activities

The processing record SolerWorks maintains for your account, aligned to GDPR and LGPD. Ready to slot into your own records.

GDPRLGPDPrivacyDOCXUpdated 20 Sep 2026
Preview structure

What it records

  1. Client and engagement
  2. Categories of processing
  3. Data subjects
  4. Personal data
  5. Location
  6. Transfer mechanism
  7. Security measures
  8. Retention

How it reads

One line per engagement. Location is always your environment, and the transfer mechanism is the EU–Brazil adequacy decision.

Security Incident Notification Protocol

A clear notification protocol with one structured form. You get the facts early enough to meet your own regulatory deadline, then updates as they develop.

Incident protocolPrivacy · securityDOCXUpdated 20 Sep 2026
Preview structure

What the notice covers

  1. Client, engagement, notifier, date and time in UTC
  2. When it was discovered and when it occurred
  3. What happened and which systems are affected
  4. Who is affected, and roughly how many
  5. What data is involved
  6. Likely consequences
  7. Actions taken and actions proposed
  8. Point of contact, then a dated update log

How it reads

One form per incident, with a running update log your team can cite directly in its own incident record.

Enterprise Audit Response Cover

Send your audit request list. Get back one signed, indexed evidence bundle, with every document mapped to the item you asked for.

AuditLegal · vendor riskDOCXUpdated 20 Sep 2026
Preview structure

Sections

  1. Recipient, client entity and audit reference
  2. Covering summary
  3. Evidence index: request item, response, document, version
  4. Signature

How it reads

Your request list becomes the index. Each row points to one versioned document, so the whole response files as a single bundle.

Deletion and Deprovisioning Certificate

A seven-step offboarding checklist that ends in a signed certificate. Proof that access is closed and nothing was retained.

OffboardingPrivacy · securityDOCXUpdated 20 Sep 2026
Preview structure

Checklist

  1. Access revoked
  2. Devices and tokens returned
  3. Personnel register updated
  4. Data returned or deleted
  5. Open privacy requests handed over
  6. Accounts settled
  7. Records archived

Certificate

States the data and systems covered, the method and the date, signed by SolerWorks. See the full protocol.

Agreements and legal basis

For your counsel

The agreement templates are shared with verified reviewers, not published. Ask for them with the audit dossier and they go to a named person at your company.

Data processing agreement

Between SolerWorks and your company. Data roles, the client-contained perimeter, sub-processors, incident notification, audit support and certified deletion.

On request

Engineer security onboarding

Signed by every engineer before access. Perimeter rules, confidentiality and the device baseline. English and Portuguese.

On request

Partner services agreement

Between SolerWorks and the delivery partner. Shared with partners during onboarding.

Partners only
Counsel-ready explainer

The EU–Brazil adequacy framework

Who signs what, the legal basis for access from Brazil, and the questions legal teams ask. Open to read, print and cite.

Read the framework

Sub-processor transparency

A direct processor model. No hidden supply chain.

You contract with the processor itself. The only people who reach your data are engineers SolerWorks has contracted, each named in a register you can inspect.

Declaration

Zero sub-processors.

SolerWorks uses no hosting, storage, analytics or AI vendor for your data, because it holds none of it. Every engineer is contracted by SolerWorks directly and works under its authority, inside your environment. Your delivery partner directs the work. It holds no credentials in your environment and receives none of your data, so it sits outside the processing chain.

Sub-processor declaration, per account · last changed 20 Sep 2026
Party or categoryRoleData heldApprovalStatus
Your delivery partnerDirects the work. No access to your environment or your dataNoneNot applicableNot a sub-processor
Infrastructure, hosting and storageNot used for your dataNoneNot applicableNone engaged
Analytics and AI toolingNot used for your dataNoneNot applicableNone engaged

Your written consent first

SolerWorks engages no sub-processor unless you have agreed to it in writing beforehand.

A register of people, not vendors

Every engineer with access is named in a live register, with role, systems and access dates.

One standard for everyone

Every engineer signs the same security and privacy undertaking before you issue access.

Incident notification

Fast, structured incident response

If something goes wrong, you hear about it without delay, in a format your team can act on. The chain exists to protect your own 72-hour regulatory window. Monitoring inside your environment stays with your own tooling.

  1. T+0

    Notice

    An engineer reports a suspected event, or your team flags an issue inside your environment.

  2. At once

    Internal escalation

    Every engineer is bound to report any actual or suspected incident to SolerWorks immediately.

  3. Without delay

    You are notified

    SolerWorks sends the structured incident form to your security and privacy contacts.

  4. 72 h

    Your window, protected

    You report onward with the facts in hand. Updates follow as the picture develops.

Request the audit dossier

The completed security pack, the data processing agreement and every document above, tailored to your account. Agreement templates can be added for your counsel. Sent to a named reviewer at your company.

Write to privacy@solerworks.com

Request audit dossier

Tell us who the dossier is for. It takes under a minute.

Audit documents
Agreement templates, for counsel

We use your details only to verify the request and deliver the dossier. See the privacy notice.

Document

Loading document.