Define the controls for your work. Review the evidence together.
Agree where data is stored, which services receive it, who can act and which decisions need a record. Review the deployment, model provider and security requirements for your selected workflow before access is granted.
Assurance documentation
Review the applicable evidence with your security team before approving the engagement.
SOC 2 assurance
Review the applicable evidence
Request the current assurance documentation and review the audited entity, system scope, report period and exceptions with your security team. A public summary does not replace that review.
ISO 27001 assurance
Review the applicable evidence
Request the applicable certificate and scope for review. Confirm which entity, services and locations it covers before treating it as evidence for your engagement.
Accessibility documentation
Review the current accessibility evaluation for Nuvepro Moodle LMS.
Define your deployment requirements
Confirm the supported configuration and controls for your selected environment.
Storage and deployment
Agree the hosting location, tenant isolation, data residency and access required for the environment. Confirm the supported cloud or on-premises deployment before committing to a topology.
Identity and permitted actions
Define learner, administrator and operating-owner access. Review the SSO, role mapping and permission controls supported by the selected environment, including what an agent may do without human approval.
Encryption and key ownership
Review encryption in transit and at rest, key ownership and any customer-managed key requirement. Record the applicable configuration and evidence in the engagement's security review.
Model-provider data flow
When an external model API is used, the request data is sent to that provider over an encrypted connection. Review its retention terms and account settings. An approved model hosted inside your network can keep inference there; review other connected services separately.
Configurable per engagement
Agree the scope during your InfoSec walkthrough and record the commitments in the applicable agreement and security response.
Audit evidence and retention
Agree which prompts, outputs, tool actions, human decisions and administrative events must be recorded. Confirm available logging, retention, access and export mechanisms for the selected environment; do not assume every action is captured automatically.
Practice-environment controls
Agree permitted data, clipboard and file-transfer policies, credentials and connected services. Confirm which restrictions the selected lab and customer endpoint can enforce before practice begins.
Providers and data handling
Review the services that process engagement data, including hosting, identity and model providers. Confirm the applicable data-processing terms, disclosure and any onward transfer with your security and legal owners.
Assurance and security review
Bring your security questionnaire and required evidence. Agree the documentation, test reports and contractual controls needed for the selected scope. Certification and legal compliance must be assessed against the actual service and deployment.
Agree the requirements before use
Your security and legal owners review the requirements, supporting evidence and commitments.
Frequently Asked Questions
Need to send your InfoSec questionnaire?
Bring the questionnaire, data-flow requirements and assurance evidence your security team needs. Confirm the applicable scope and supporting documentation in a walkthrough.
Discuss Security Requirements