Security and continuity
Buyers of document work ask the same questions in roughly the same order. Here are the answers — including the ones that are "no."
What we are not
We are not ISO 27001 certified and we do not hold a SOC 2 attestation. If either is a hard gate in your procurement process, we will not clear it, and it is better that you know that on this page than three weeks into an evaluation.
We are also not the low-cost, high-volume option. What we offer instead is an operation where the people handling your materials are known, supervised and accountable — and a record of being audited by clients who had every reason to be difficult.
What we have been audited on
Our operations have been audited annually by financial-services clients — a sector with very little tolerance for a weak answer. Those audits covered both physical security and information security, and were accompanied by penetration testing.
Being audited by a demanding client every year is not the same thing as a certification, and we will not present it as one. It is arguably a harder test: an auditor working for a client who will walk has different incentives from one working to a checklist.
The controls behind that
- Background-checked personnel. Everyone who handles client materials has been screened.
- Signed confidentiality agreements. Staff, and any additional resources brought in for a project.
- Access-controlled production floor. Entry is controlled, visitors are logged, and materials are not left out between shifts.
- Documented disposition. Every project ends with a written record of what happened to the originals — returned or destroyed — agreed before the work starts rather than after it ends.
Business continuity
A client audit required us to hold a pandemic continuity plan years before 2020. We wrote one, and privately thought it was a box-ticking exercise.
In 2020 we ran it. It worked.
We mention this not for the irony but because continuity planning is the section of a vendor questionnaire most often filled with intentions. Ours has been executed under the exact conditions it was written for.
Regulated health data
We have operated as a HIPAA Business Associate under signed agreements for covered-entity clients, and we know what that obligation involves — the agreement itself, the access controls behind it, and the breach-notification timeline.
We do not currently hold protected health information, and we are not currently party to a Business Associate Agreement. If an engagement involves PHI, we execute a BAA before any materials move.
Where the work happens
Our operations are in Michigan and Ohio, and that is where work runs by default. Nothing is quietly subcontracted. Where a client's own process calls for something different — a front-end mail and scanning operation feeding an offshore back end, for example — that is scoped and agreed in writing before anything moves.
Professional standing
Indata Technologies holds memberships in AIIM and ARMA International. Greg Lavigne, who runs the company, served for years on the board of AIIM's Michigan chapter.
Memberships are not certifications and we will not present them as such. They say that this business operates inside its profession rather than alongside it.
What we will send you
On request, and under NDA where appropriate: our responses to your security questionnaire, a certificate of insurance, and a walkthrough of how your specific materials would be received, handled, stored and returned or destroyed.
If your questionnaire asks something we cannot answer well, we will tell you that rather than write something vague and hope it passes.
Common questions
Are you ISO 27001 certified or SOC 2 attested?
No, and neither is in progress. If either is a hard gate in your procurement process we will not clear it.
Have you been independently audited?
Our operations have been audited annually by financial-services clients, covering both physical and information security, accompanied by penetration testing. That is a client audit, not a certification, and we do not present it as one.
Are your people background checked?
Yes, everyone who handles client materials, and all of them work under signed confidentiality agreements.
Can you handle protected health information?
We have operated as a HIPAA Business Associate under signed agreements. We do not currently hold PHI and are not currently party to a BAA. If an engagement involves PHI we execute a BAA before any materials move.
Will you complete our security questionnaire?
Yes, and under NDA where appropriate. If it asks something we cannot answer well, we will tell you that rather than write something vague and hope it passes.
What happens to our materials when the work is finished?
Returned or destroyed, per what was agreed before the project started, with a written record of which.
Send us your questionnaire
We would rather answer the hard questions early than discover a mismatch after the materials arrive.