Everything your ITreview will ask for.
Six policies, written to answer a HECVAT truthfully. Where a control does not exist yet, the document says so instead of implying it does.
Your records never reach our servers.
That is the architecture, not a promise about our uptime.
Six documents, written for a security reviewer.
Each one describes what Kenii actually does today. Send any of them straight to the person running your vendor assessment.
Information Security Policy
What Kenii secures, the standing rules enforced in code review, change control, patching, and how secrets are held. Ends by naming the limits of a small company rather than implying a security office exists.
Data Privacy Policy
Where institutional data lives, what the product holds, and a full table of every outbound request the software makes from your server, so your team can review or block any of them.
Incident Response and Breach Notification
How to report a security issue, the six steps that follow, and the notification clock by severity. Every institution running an affected version is told, not only the one that reported it.
Business Continuity and Disaster Recovery
What keeps running if Kenii goes dark, the 30-day offline license grace, who owns backups, and an honest statement of key-person risk.
Personnel, Access and Lifecycle
Who can reach your site, what they sign first, how access is limited, and the same-day checklist when someone leaves.
Third Parties and Subprocessors
Every third party the product calls, what each receives, and which are optional. Google Fonts and video embeds are named specifically because both send a visitor request off your domain.
The controls we do not have yet.
A vendor questionnaire is easy to answer optimistically. These are the places Kenii answers no today, listed here rather than buried inside a document.
The continuity plan is untested
The recovery plan is written and the objective is stated, but it has not been tested end to end. The first test is scheduled and the result will be recorded on that page.
Security training is not yet running
Annual security awareness training is defined and scheduled, but it is not operating and no completion has been recorded.
No formal third-party assessments
Kenii reviews what data a provider would receive before adopting it, but does not run formal security assessments or hold negotiated breach-liability terms with each provider.
No multi-state background screening
Not run as standard. Where a contract requires it for personnel touching your environment, screening is arranged for the named individuals as a condition of that contract.
Hand these toyour reviewer.
If your assessment needs something these do not cover, ask. We will tell you whether we do it, rather than answering yes and working it out later.