Security Questionnaires, SIG and CAIQ (Gated)
8 source changes since auditThis page confirms that prepared security-questionnaire responses exist and explains how to request them. The completed responses are gated; they are not authored in these public docs.
What it is
Citrate keeps prepared responses to the standard third-party security questionnaires, the Shared Assessments SIG and the Cloud Security Alliance CAIQ, along with customer-specific variants. Each response is backed by the evidence in the private compliance corpus, so a reviewer reads answers that match the package, not answers written for the occasion.
We treat completed responses as confidential. They carry the same security-sensitive detail as the full compliance package, so we do not reproduce any answers, control mappings, or evidence on this page or anywhere in the public docs.
How to request access
Access is for procurement and security-review teams running vendor due diligence, as named principals under a non-disclosure agreement.
- Ask through your commercial contact at Citrate, naming the questionnaire you need.
- We confirm your role and put the non-disclosure agreement in place.
- We share the completed SIG or CAIQ response from its private home.
Access and canon
The completed responses are confidential. They draw on the gated full compliance package and are served at request time from their private home, under a non-disclosure agreement, to named recipients only. They are never copied into this documentation tree, and the public build never includes them. Every access is logged. The sanitized public summary, which anyone may read, is at Compliance posture.
Source and verification
Private source: the citrate-compliance corpus. Audited against citrate-compliance SHA 8757357. Status: Implemented (prepared responses exist and are maintained); no answers or mappings are shown here.