# Security reviews

> Everything a security, legal or IT review needs from Immiscible, in one download, with the gaps named.

Source: https://immiscible.fly.dev/docs/security/security-reviews

If your company reviews a supplier before it signs, you should not have to wait for us to answer a spreadsheet. The review pack is free to download and needs no form:

**[Download the security review pack](https://immiscible.fly.dev/trust/pack.zip)** (zip, Markdown and JSON)

It holds:

- a security questionnaire answered in the shape of the CSA CAIQ v4 domains and the SIG Lite themes, with an AI section;
- the architecture and a data-flow diagram;
- access control: SSO, SCIM, roles, step-up and the audit log;
- incident response and breach notice;
- business continuity: the backups we actually run, and the recovery objectives we have and have not measured;
- the sub-processor list;
- `trust.json`, generated by the service at the moment you download, so it reflects this deployment's configuration rather than a document someone wrote.

## What we have not done yet

We hold no SOC 2 report or ISO/IEC 27001 certificate, and no independent firm has tested the service yet. SAML 2.0 single sign-on is supported beside OpenID Connect, and has not yet had an outside review. The pack says each of these where it matters, with the plan. The same list is on [the Trust page](https://immiscible.fly.dev/trust).

## Machine-readable

[`/trust.json`](https://immiscible.fly.dev/trust.json) is the same control list on its own, for tools that collect supplier evidence. [`/.well-known/security.txt`](https://immiscible.fly.dev/.well-known/security.txt) says where to report a vulnerability.

If your questionnaire asks something the pack does not answer, [send it to us](https://immiscible.fly.dev/contact?topic=security). A founder reads every message.
