Financial Services (Payments) · Enterprise · $0 · owned by Yusuf Abdel-Rahman
Steve has not written one for this account. Everything it would read is below.
Every record Steve is allowed to cite
Staff Data Engineer
Security Architect
Financial Services (Payments) · Enterprise · $0 · owned by Yusuf Abdel-Rahman
Steve has not written one for this account. Everything it would read is below.
Every record Steve is allowed to cite
Staff Data Engineer
Security Architect
VP Engineering
Next step: Return the completed CAIQ and pen test remediation evidence by 2026-07-24
Sentinel's vendor review team requested the current SOC 2 Type II report and the most recent third-party penetration test summary. Both shared under NDA. Their reviewers came back with two follow-up questions on the remediation status of the medium findings, which remain unanswered.
Tom Buckley asked for written confirmation that EU cardholder-adjacent data never leaves the EU during a regional failover. Confirmed that failover targets a secondary EU zone only, but our published DR runbook does not yet state it explicitly, so the customer is holding the item open until the runbook is updated.
Security review raised customer-managed encryption keys with HSM-backed custody and a 90 day rotation policy. Escalated to product: envelope encryption with customer-supplied keys is on the roadmap but not generally available, and no committed date has been given to the customer.
Elena said signature has moved past the July approval cycle into the next one. Aisha reported that Tom's review is still open on the key custody finding, that the audit log streaming item was closed after the Splunk HEC integration was demonstrated, and that the TLS 1.2 item was closed against the published endpoint deprecation notice. Elena asked what the technical onboarding timeline looks like once paper is signed and said she wants the EU region live before the end of the calendar year.
Tom walked his threat model against our reference architecture and logged three findings: customer-managed key custody, audit log streaming into their Splunk instance, and confirmation that TLS 1.2 endpoints are retired. Aisha confirmed the functional evaluation closed out all seven exit criteria including the 40 million row settlement reconciliation test, which ran in 11 minutes against their 30 minute target. Tom asked for the CAIQ and the pen test remediation evidence before he would move the review to a recommendation.
VP Engineering
Next step: Return the completed CAIQ and pen test remediation evidence by 2026-07-24
Sentinel's vendor review team requested the current SOC 2 Type II report and the most recent third-party penetration test summary. Both shared under NDA. Their reviewers came back with two follow-up questions on the remediation status of the medium findings, which remain unanswered.
Tom Buckley asked for written confirmation that EU cardholder-adjacent data never leaves the EU during a regional failover. Confirmed that failover targets a secondary EU zone only, but our published DR runbook does not yet state it explicitly, so the customer is holding the item open until the runbook is updated.
Security review raised customer-managed encryption keys with HSM-backed custody and a 90 day rotation policy. Escalated to product: envelope encryption with customer-supplied keys is on the roadmap but not generally available, and no committed date has been given to the customer.
Elena said signature has moved past the July approval cycle into the next one. Aisha reported that Tom's review is still open on the key custody finding, that the audit log streaming item was closed after the Splunk HEC integration was demonstrated, and that the TLS 1.2 item was closed against the published endpoint deprecation notice. Elena asked what the technical onboarding timeline looks like once paper is signed and said she wants the EU region live before the end of the calendar year.
Tom walked his threat model against our reference architecture and logged three findings: customer-managed key custody, audit log streaming into their Splunk instance, and confirmation that TLS 1.2 endpoints are retired. Aisha confirmed the functional evaluation closed out all seven exit criteria including the 40 million row settlement reconciliation test, which ran in 11 minutes against their 30 minute target. Tom asked for the CAIQ and the pen test remediation evidence before he would move the review to a recommendation.