org.tech / Resources / Posture questionnaire Glass box. Seven sections

Publishing the questions costs us the advantage of asking them cold. That trade is the whole argument.

See the questions before the call.

Most vendor security questionnaires arrive from the buyer and are answered by a sales engineer. This one runs the other way: it is our instrument, we walk it with you during discovery, and it is published here in summary so your security owner can read every question before sitting down with us. Nothing in it is a trick, and two of its disclosures are ones most vendors would keep until after signature.

What this is.

QUESTIONNAIRE · 01

A client-facing instrument that captures what your deployment must do, surfaces the tradeoffs honestly, and ends in a configuration rather than a document. It never assumes a requirement without asking.

What it is not

It is not an audit, not a contract, and not a substitute for your own program. It captures technical posture, so it says nothing about your organizational controls, your audit scope, your choice of auditor, or application-level security review. Those remain yours, and the deployment is necessary rather than sufficient for any compliance objective you hold. See compliance alignment.

Three jobs, honestly named.

QUESTIONNAIRE · 02

An instrument like this is usually a sales artifact pretending to be a technical one. This one does three jobs, and all three are named here.

01

Qualification.

It surfaces what prompted the evaluation and who holds the veto, early enough to matter. It also surfaces the cases where we are the wrong answer: a requirement the chosen region cannot support, or a control you need that we do not have. Finding that in discovery is cheaper for you than finding it in month three.

For both sidesDiscovery
02

A trust artifact.

Asking a buyer in writing, before any sale, whether they understand that we hold no third-party attestation is the strongest version of the glass-box claim we can make. The same is true of the residency disclosure. A vendor who publishes the questions it will ask has less room to manage the answer.

WrittenBefore signature
03

Configuration input.

The answers become your deployment's committed posture configuration, not a summary of a conversation. Any override carries a written reason, and it shows up as a standing exception on your plan page inside the product, where you can read it whenever you like rather than when we remember to mention it.

Drives the buildVisible in product

The seven sections.

QUESTIONNAIRE · 03

What each section establishes, then the questions themselves. These are representative rather than exhaustive: the instrument carries more, and none of it is harder than what is here.

SectionWhat it establishesWhat it drives
1. Context and current AI landscapeWhat you do, how many people, what is already in use and what prompted thisScope, first capabilities
2. Data residencyStorage, processing and inference as three separate questions, with the tradeoff disclosedRegion, routing, the pin
3. Security controlsEncryption, identity and multi-factor, audit logging, retention, networkMost of the posture tier
4. Operational requirementsAvailability and recovery expectations, hosting shape, change management, administratorsTopology, approval rules
5. Compliance programWhat you hold, what your own customers ask you for, what you expect from usEvidence pack, disclosures
6. Posture recommendationThe tier the answers map to, and every override with its written reasonThe resolved posture
7. Posture commitmentYour approval of that posture as the deployment's configurationThe build, and the evidence

Sections 1 to 4 are captured below; 5 to 7 in the next section. Terms used in the questions are defined in the glossary.

1. Context and current AI landscape

2. Data residency

3. Security controls

4. Operational requirements

One answer that is already settled

Model invocation logging is not one of the choices. It runs at every deployment, and it deliberately carries no prompt or answer text: model, caller identity, latency, token counts. So the question a reviewer should ask here is what the record is used for, and the answer is metering settlement and evidence. Administration.

Recommendation and commitment.

QUESTIONNAIRE · 04

The last three sections turn answers into a configuration. This is where an override stops being a conversation and becomes a recorded exception with your name on it and ours.

5. Compliance program

6. Posture recommendation

7. Posture commitment

The disclosures.

QUESTIONNAIRE · 05

Two of these you acknowledge in writing before anything is built. They are the reason the instrument exists in this form, and they are the two things a competitor would leave until after signature.

Disclosure one · attestation

org.tech provides technical controls designed to align with SOC 2 Trust Services Criteria and ISO/IEC 27001. We hold no third-party attestation, of either type. The deployment supports your compliance program; it does not replace your own organizational controls or, where you need one, your own audit engagement. A SOC 2 report is issued by an independent audit firm, and no vendor can hand you one. Compliance alignment.

Disclosure two · residency costs capability

Pinning inference to Canada limits which models you can use, and we put the numbers in front of you before you choose. Every current frontier model routes outside Canada. The in-region generation set is previous-generation: Claude 3 Sonnet and Haiku, Llama 3 8B and 70B, Mistral Large 24.02, Mixtral 8x7B and Mistral 7B. Sound for retrieval, summarising and classification; materially weaker on reasoning, long context and tool use. A second, OpenAI-compatible model plane has no Canadian region at all, so a pinned deployment cannot serve it under any posture. Data residency.

104models
Catalogue · 5 Sep 2026
13
In-region · in Canada
1
Routed · within Canada only
72
Served · US and global

The remaining 18 are reachable but processed outside Canada. The catalogue is generated from the provider's live model list by a script and classified by where inference actually runs, so these figures are read from the product rather than typed into copy.

Disclosure three · every downgrade is visible

Any control set below the recommended tier's default carries a written reason in the posture, and that reason becomes a standing exception rendered to you inside the product, on the same page as your resolved controls. We would rather you read what we have not closed than discover it. Evidence pack.

How to get the whole thing.

QUESTIONNAIRE · 06

There is no download form on this page, and there is no gated version with better content. The full instrument is walked with you in the assessment, because half its value is in the conversation each question starts.

The recommendation is not "trust Sam". It is: own the environment, inspect the evidence, and keep the exit open.Why the questions are published

⎯⎯ Book the strategic assessment ⎯⎯

Your private AI, inside your control ·

Read the questions, bring your objections, and we will complete the instrument together in the session.