App Locksmith
Sample

This is a sample. Northwind Labs isn't a real company, the customer asking isn't real, and none of this describes a real client. I wrote it to show exactly what you get, down to the wording.

Completed security questionnaire: Northwind Labs

A three-person company answering a 94-question vendor security review from an enterprise customer. Twelve of the answers are shown here, including all three we answered no to.

Prepared for
Northwind Labs
Responding to
A prospective enterprise customer's vendor security review
Questions
94, of which 12 are shown here
Work done
2 to 6 March 2026
Completed
6 March 2026
Reference
AL-2026-011

How these answers are written

Every yes in this document is true, because I either checked it or fixed it first. That is the whole method, and it is the only thing that makes the rest of the answers worth anything.

Three answers are no. A no with a reason and a plan does not lose deals. Security teams read these for a living and they can tell when a small company has ticked yes to a control it does not operate. That is what loses deals, usually six months later when someone asks for evidence.

Where a control did not exist and could be put in place in days, I put it in place and the answer says so. Where it could not, the answer says what happens instead. Nine of the twelve answers below were made true during the work; four of them had to be built first.

The one-page summary

This goes out with the questionnaire, and again to the next customer who asks before they send a spreadsheet of their own. It is the single most reused thing I produce.

Northwind Labs — security summary

March 2026

What we are
A three-person company in Bristol. One product, used by 40 organisations. No offshore development, no subcontractors with access to customer data.
Where your data lives
Managed Postgres in London (AWS eu-west-2). Encrypted at rest. Nothing is copied outside the UK except as listed in our subprocessor list.
Who can reach it
Two named people. Both accounts require a hardware key. Administrative access is logged and the log is kept for 400 days.
How it is protected
Traffic is TLS 1.2 or better. Access between customer accounts is enforced in the database, not only in the application. Backups run nightly and are restored and timed quarterly; the last test took 22 minutes.
What we do not have
No SOC 2 and no ISO 27001. We are too small for either to be honest this year. We have an independent security review, dated and by a named engineer, and we will answer any question you put to us.
If something goes wrong
We have a written incident plan. We will tell an affected customer within 24 hours of confirming an incident, before we know the full extent, and keep telling you as we learn more.
Who to contact
[email protected] reaches a person, not a queue. Named security contact: the founder.

The answers

Shown as they were submitted. Where something had to be built or changed to make an answer true, the answer says what changed and when.

Is customer data encrypted in transit?

Yes

All traffic to the application and between the application and its database uses TLS 1.2 or better. Plain HTTP requests are redirected and HSTS is set. Verified during this review.

Is customer data encrypted at rest?

Yes

The managed Postgres instance and its backups are encrypted at rest by the provider (AWS eu-west-2). Uploaded files are stored encrypted in the same region.

Is multi-factor authentication enforced for administrative access?

Yes

Both accounts able to reach customer data require a hardware security key. There are no shared logins and no accounts exempt from the requirement.

What I changed to make this true

It was on for the application but not for the hosting account or the domain registrar, which is where it matters most. Both were enforced on 3 March 2026, and a third dormant administrator account was removed.

Do you hold SOC 2 Type II or ISO 27001 certification?

No

Northwind is three people and neither is realistic this year. Rather than promise one, here is what we offer in its place: this questionnaire answered honestly and in full, an independent security review dated March 2026 by a named engineer, the one-page summary attached, and a named person who will answer any follow-up question directly. If certification is a hard requirement for your organisation, we would rather know now than at contract stage.

Have you had a penetration test in the last twelve months?

Partly

Not a penetration test, and we will not call one something it is not. What we have is an independent security review completed in March 2026: source code, configuration, database rules and the running application tested as an authenticated user and as an unauthenticated stranger. The difference is that a penetration test is adversarial and time-boxed against a live target, usually by a team. If you require a penetration test specifically, we will commission one; we would ask for your scope requirements so it answers your question rather than ours.

Do you perform background checks on personnel with access to customer data?

No

There are three of us and two founders hold all access. There are no employees to check. If Northwind hires someone with access to customer data, checks will start at that point, and we will tell you. We would rather answer this no than tick a box for a process we do not operate.

Do you have a documented incident response plan?

Yes

One page: who is called, what is checked first, who is told and when, and who speaks to customers. It commits us to telling an affected customer within 24 hours of confirming an incident, before the full extent is known. Attached as appendix B.

What I changed to make this true

It did not exist. It was written on 4 March 2026 and walked through once against a worked scenario.

Are backups taken, and are they tested?

Yes

Nightly, retained 35 days, encrypted, held by the database provider. A restoration test is now run quarterly, timed and recorded.

What I changed to make this true

Backups had run nightly for two years and had never once been restored. We restored one to an isolated database on 4 March 2026: it took 22 minutes and was complete. Until that test, the honest answer to this question would have been no.

Is administrative access to customer data logged?

Yes

Administrative actions are written to an append-only log recording who, what, which record and when, retained for 400 days.

What I changed to make this true

Added on 5 March 2026. Activity before that date is not logged, and we would tell you that rather than let you assume otherwise.

Do you use subprocessors? Please list them and the data each receives.

Yes

Four. AWS (eu-west-2): all application and customer data, hosting. Stripe (EU/US): billing contact and payment details, no product data. Postmark (EU): email addresses and message content for transactional email. Sentry (EU): error reports, with user identifiers stripped. The list is maintained at northwindlabs.example/subprocessors and we give 30 days' notice before adding one.

Can our data be exported and deleted on request?

Yes

Export as CSV or JSON within 5 working days of a request. Deletion from the live system within 30 days. One nuance worth stating rather than hiding: deleted data persists in encrypted backups until those backups age out, which is up to 35 days after deletion. Nothing restores from them selectively, and the backups are not accessible to the product.

Do you have a vulnerability disclosure contact?

Yes

[email protected], reaching a person, published on the website and in a security.txt file at the standard location. We answer within two working days.

What I changed to make this true

There was no published contact before 5 March 2026. A researcher who found something had no way to tell us except the general support address.

What this pack is, and what it isn't

  • These answers describe Northwind Labs on 6 March 2026. Controls change; a questionnaire is a snapshot and should be dated, as this one is.
  • Answering a questionnaire well is not the same as being secure, and no honest vendor should imply it is. It means the answers can be relied on.
  • Where an answer says something was changed during the work, the date is given so a customer can see what was long-standing practice and what was built last week. Hiding that distinction is the most common way these documents mislead.
  • I am not a certification body and this is not an audit. It is the work of one named engineer alongside the vendor, and every answer can be checked.

Nate Parker

App Locksmith, applocksmith.com

Completed 6 March 2026. I join the call if the customer's security team wants to go through any answer.

Got a questionnaire sitting in your inbox?

I check your app against every question, fix what would fail, and write the answers with you. Every yes is true, and the ones that have to be no come with a reason and a plan.