TrustDesk
Back to workspace

Bluepeak Retail

On Track

qn-004 · Retail & E-commerce

Deal stage
Expansion
Deal value
$150,000
Questions
5
Received
May 22, 2026
Due
Jun 25, 2026 (24d)
Encryption & Data Protection · q-017

How is cardholder data encrypted and segmented per PCI DSS?

100confidence
Auto-Approved
Drafted response

Cardholder data is encrypted at rest with AES-256 and processed in a logically segregated environment with network controls isolating production workloads.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse4/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Routed toAuto-Approved

Why this verdict

  • Strong control match on current, approved evidence with no sensitivity flags — cleared to auto-approve.
Cloud & Infrastructure Security · q-018

Describe your cloud hosting architecture and tenant isolation.

95confidence
Auto-Approved
Drafted response

The platform runs on a major cloud provider in a logically segregated, multi-tenant architecture with security groups and private subnets isolating production.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Routed toAuto-Approved

Why this verdict

  • Strong control match on current, approved evidence with no sensitivity flags — cleared to auto-approve.
Vendor & Third-Party Risk · q-019

What is your vendor and third-party risk management process?

81confidence
Suggested
Drafted response

Vendors are risk-assessed before onboarding and reassessed periodically by data sensitivity and criticality, with security and privacy requirements flowed down contractually.

Confidence factors

  • Control Match3/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language3/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity3/4weight ×1.0

    How standard and well-bounded the question is.

Routed toSecurity Enablement

Why this verdict

  • Confidence score of 81/100 lands in the Suggested band — a solid draft that benefits from a light review before sending.
Vulnerability Management · q-020

How quickly are critical patches applied to internet-facing systems?

72confidence
Needs Review
Drafted response

Critical patches to internet-facing systems are prioritized and remediated within defined SLA windows and tracked to closure.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived0/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse4/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity3/4weight ×1.0

    How standard and well-bounded the question is.

Mapped evidence

Routed toSecurity SME

Why this verdict

  • Capped at Needs Review: mapped evidence is expired, overriding a numeric score of 72. A confident answer on stale evidence is still a stale answer.
Privacy & Data Retention · q-021

Do you support customer-managed data deletion requests?

84confidence
Needs Review
Drafted response

Yes. Data is retained only as long as necessary, and deletion or return is supported within the period defined in the data processing agreement.

Confidence factors

  • Control Match3/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language3/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Routed toPrivacy / Data Protection

Why this verdict

  • Capped at Needs Review: Privacy & Data Retention carries legal/privacy exposure and always requires human sign-off, regardless of the 84 confidence score.