Skip to content

Security questionnaire answers

Version 1.0, September 27, 2026. We answered 109 questions, in our own words, covering all 17 domains of the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire (CAIQ v4), each mapped to its Cloud Controls Matrix v4 control. This is not the official CAIQ form: the questions are the ones security and procurement teams usually ask, grouped by the questionnaire’s domain.

Every answer describes what WPMaven does today. Where we do not do something, the answer is “No” and says what we do instead. We hold no SOC 2 report and no ISO 27001 certificate, and no outside company has tested our security yet.

The answers at a glance

AnswerQuestions
Yes29
Partial43
No37
Total109

“Ownership” says who runs each control: WPMaven, our cloud provider (inherited), you, or both (shared).

Audit and assurance

IDQuestionAnswerOwnershipDetail
Q001Do you have a documented audit and assurance policy that is reviewed at least once a year? (A&A-01)NoWPMavenNo. We have no written audit policy. We review our own code and infrastructure in structured internal reviews (the latest in September 2026) and keep their findings and fixes in our engineering records.
Q002Are independent audits or certifications (SOC 2, ISO 27001, PCI DSS) performed at least once a year? (A&A-02)NoWPMavenNo. We hold no SOC 2 report, no ISO 27001 certificate and no PCI DSS certification, and no independent firm has assessed us yet. Card payments run on Stripe’s own payment pages, so card numbers never reach us.
Q003Are your security assessments planned according to risk? (A&A-03)PartialWPMavenPartial. Our internal reviews focus on the paths with the most risk for customer data: sign-in and sessions, the checks that each request touches only the caller’s own businesses and sites, payments, our website servers and our WordPress plugin. We have no written annual assessment plan.
Q004Do you verify compliance with the legal, regulatory and contractual requirements that apply to you? (A&A-04)PartialWPMavenPartial. We document how we meet the GDPR in our Privacy Policy, our Data Processing Agreement and this answer set. No outside party has audited that compliance.
Q005Are findings from audits and assessments tracked and remediated? (A&A-06)YesWPMavenYes. Every finding from our reviews is recorded with its severity and is fixed or scheduled. Our September 2026 reviews found issues that could have led to account takeover, data exposure or runaway cost; each of those was fixed and checked again before launch. Lower-risk hardening items stay on our list with a plan.

Application and interface security

IDQuestionAnswerOwnershipDetail
Q006Do you have a documented application security policy? (AIS-01)NoWPMavenNo. We have no written application security policy. The practices in this section (reviewed changes, automated tests, access checks on every request) are how we apply it.
Q007Do you follow a secure development process, with code review before release? (AIS-04)PartialWPMavenPartial. Every change goes through a merge request on a development branch and an automated test pipeline, and production is updated only when the founder promotes the development branch. Security rules have their own automated tests, for example that a request can touch only the caller’s own businesses and sites, and that messages between our servers and your site’s plugin are signed. We do not follow a formal secure development framework, and a second reviewer is not required on every change.
Q008Do you run automated security testing (static analysis, dynamic scanning, dependency scanning) in your pipelines? (AIS-05)NoWPMavenNo. Our pipelines run our own automated tests, including security regression tests, on every change. They do not run static analysis, dynamic scanning or dependency vulnerability scanning tools.
Q009Are deployments automated and controlled? (AIS-06)YesWPMavenYes. Production is deployed by our pipeline from the production branch. The pipeline signs in to our cloud with a short-lived federated identity rather than a stored key, and secrets are injected from a managed secrets service at deploy time, never stored in the code.
Q010Are application vulnerabilities remediated within defined time frames? (AIS-07)PartialWPMavenPartial. We fix findings by severity, and anything that could expose customer data or accounts is fixed before it ships. We have no written deadlines per severity.
Q011Are your APIs authenticated, authorized and protected against abuse? (AIS-02)YesWPMavenYes. Every call from the dashboard that reads or changes an account is authenticated with a signed session token and checked against the owner of the business or site it touches, and calls from your site’s plugin use that site’s own credentials. Requests are rate limited per user or per IP address, sign-in has its own tighter limits, only our dashboard’s own address may call the API from a browser, and the first step of building a site is protected by a bot check.
Q012How do you protect against AI-specific risks such as prompt injection acting on another customer’s data? (AIS-04)PartialWPMavenPartial. The AI team cannot act on another customer’s account: the account and the site it works on are fixed by the signed-in session, never by what the model writes. After your website is first built, nothing the team produces goes public or changes your live site until you approve it, and every action it takes is logged. We have no formal AI risk assessment.

Business continuity and resilience

IDQuestionAnswerOwnershipDetail
Q013Do you have a documented and tested business continuity plan? (BCR-01)NoWPMavenNo. We have no written business continuity plan and have not run a continuity exercise. What we do have is described below: daily database backups, nightly website backups, and managed services that restart automatically.
Q014Is customer data backed up? How often, where, and for how long? (BCR-08)YesWPMavenYes. The application database is backed up automatically every day, and the last 7 daily backups are kept. Every website we host (its database and its files) is backed up every night to separate storage in the European Union (Belgium); that storage keeps each replaced backup for 7 more days. Backups are encrypted at rest.
Q015Can you restore data to an earlier point in time? (BCR-08)PartialWPMavenPartial. The application database can be restored to any of its last 7 daily backups; point-in-time recovery is not turned on. For hosted websites, our restore tool brings back the latest nightly backup, and our team can recover an earlier night from the 7-day retention of replaced backups.
Q016Do you test restores from backup on a schedule? (BCR-10)NoWPMavenNo. A restore path for hosted websites exists in our tooling, but we do not test restores on a schedule and have no restore test on record.
Q017Have you defined recovery time (RTO) and recovery point (RPO) objectives? (BCR-03)PartialWPMavenPartial. Our recovery point is at most 24 hours for hosted websites and for the application database, because both are backed up daily. We have not set or tested a recovery time objective.
Q018Is the service redundant across data centers or regions, with a disaster recovery site? (BCR-11)NoWPMavenNo. WPMaven runs in one cloud region, in Belgium. The application restarts automatically if it fails, but the database has no standby replica and there is no second region or disaster recovery site.
Q019Do you offer an uptime commitment and tell customers about outages? (BCR-07)PartialWPMavenPartial. We do not offer an uptime commitment or service credits today, as our Terms say, and we will not set one until we have 90 days of measured data. Our status page (wpmaven.ai/status.html) shows what our automated uptime checks measure for each part of the service, and says “No data yet” until they report. We publish known incidents there by hand.

Change control and configuration

IDQuestionAnswerOwnershipDetail
Q020Do you have a change management process? (CCC-01)PartialWPMavenPartial. We have no written change management policy. In practice every change is a merge request into a development branch, runs the automated test pipeline, and reaches production only when the founder promotes the development branch.
Q021Are changes tested before they reach production? (CCC-02)YesWPMavenYes. Each repository runs its automated test suite in the pipeline before a build. For the application, the pipeline also type-checks the code, and database changes are applied as versioned migrations in their own step, with their own database user.
Q022Are production systems protected against unauthorized changes? (CCC-04)PartialWPMavenPartial. The application can be changed in production only by our pipeline, from the production branch, or by the three named people who hold administrative roles in the cloud project that runs it. Our public website and the analytics tool we operate ourselves run in a second cloud project; four named people hold administrative roles across the two. The application’s configuration is replaced on every deploy, so a setting changed by hand does not survive the next release. There is no two-person approval rule.
Q023Do you maintain configuration baselines and detect drift? (CCC-06)PartialWPMavenPartial. Our website servers are built from one versioned server image and each site runs from one versioned site image; the application’s configuration lives in its deploy pipeline. We do not run automated drift detection.
Q024Can a faulty change be rolled back? (CCC-09)YesWPMavenYes. Every release of the application is a versioned container image, so a faulty release is rolled back by deploying the previous one, and each website server image keeps its previous version for the same purpose.

Cryptography, encryption and key management

IDQuestionAnswerOwnershipDetail
Q025Do you have a documented encryption and key management policy? (CEK-01)NoWPMavenNo. We have no written encryption policy. The measures in this section are how we encrypt data and manage keys today.
Q026Is customer data encrypted at rest? (CEK-03)YesSharedYes. All customer data at rest (the database, file storage, backups and server disks) is encrypted by our cloud provider with AES-256. The access tokens for the social accounts you connect, and other third-party credentials we store, are encrypted a second time by our application with AES-256-GCM before they are written to the database.
Q027Is data encrypted in transit, including inside your network? (CEK-03)PartialSharedPartial. Connections to the dashboard and the API always use HTTPS (plain requests are redirected), the websites we host are served over HTTPS, and our edge network connects to our website servers over TLS. The application reaches its database through the cloud provider’s encrypted connector, and traffic between our own servers stays on the cloud provider’s private network and is authenticated. One internal hardening item in this area is open; details under NDA on request.
Q028Do you use strong, current encryption and signing algorithms? (CEK-04)YesWPMavenYes. AES-256 at rest, AES-256-GCM for the credentials our application encrypts itself, TLS for data in transit, Ed25519 signatures on our plugin’s releases, HMAC-SHA256 signatures on messages from our servers to your site’s plugin, and bcrypt for sign-in codes.
Q029Can customers manage their own encryption keys (bring your own key)? (CEK-08)NoWPMavenNo. We do not offer customer-managed or bring-your-own keys. Storage encryption keys are managed by our cloud provider.
Q030Are keys and secrets generated, stored and access-controlled in a key management system? (CEK-10)PartialWPMavenPartial. Application keys and secrets are kept in a managed secrets service and injected into the application at deploy time; none are stored in our code. We have no written key lifecycle procedure, and narrowing which secrets each of our services can read is an open item.
Q031Are keys rotated on a defined schedule? (CEK-12)NoWPMavenNo. We do not rotate keys on a fixed schedule.

Data center security

IDQuestionAnswerOwnershipDetail
Q032How is the physical security of the data centers ensured? (DCS-03)YesCloud providerYes, through our cloud provider. We own no servers or data centers. Everything runs in our cloud provider’s data centers, whose physical and environmental controls are covered by the provider’s own independent audits, including SOC 2 and ISO 27001.
Q033Are storage media securely wiped or destroyed at end of life? (DCS-01)YesCloud providerYes, through our cloud provider, which sanitizes and destroys storage media under its own audited procedures. We handle no physical media.
Q034Do you keep an inventory of your systems and assets? (DCS-06)PartialWPMavenPartial. Our cloud resources are listed in the provider’s own inventory and in our deploy and server-build definitions. We keep no separate asset register.

Data security and privacy

IDQuestionAnswerOwnershipDetail
Q035Do you publish a privacy policy that covers the personal data you process? (DSP-01)YesWPMavenYes. Our Privacy Policy (wpmaven.ai/privacy-policy.html) sets out what we collect, why, how long we keep it and the rights people have. It was last updated on September 25, 2026. Our Data Processing Agreement covers the data we process for business customers.
Q036When an account is deleted, is its data securely deleted everywhere, including backups? (DSP-02)PartialWPMavenPartial. When an account is erased, we take down its hosted websites and drop their databases, delete its conversations, revoke and delete the tokens of its connected accounts, and anonymize the records we must keep for tax. Its website backups are not yet removed by that process.
Q037Do you have defined retention periods, and do you delete data when they end? (DSP-16)PartialWPMavenPartial. Our Privacy Policy sets retention periods for each kind of data. When a subscription ends, its hosted websites stay online for 14 days, then are taken offline with a final backup that is kept for at least 90 days. A $1 first week that does not continue into a paid plan, and a withdrawal, get no such 14 days: the site comes down when the subscription ends. Our Terms say data is deleted 90 days after a subscription ends; that deletion is not automated yet. You can ask us to delete your account at any time, and we then erase it as described above.
Q038Do you keep an inventory of the personal data you process and document its flows? (DSP-03)PartialWPMavenPartial. Our Privacy Policy, our subprocessor list and Annex I of our Data Processing Agreement describe the personal data we hold, where it flows and where it is stored. We have not yet written our record of processing activities under Article 30 of the GDPR, and we keep no separate data-flow diagram.
Q039Do you classify data by sensitivity? (DSP-04)NoWPMavenNo. We do not run a formal data classification scheme. We treat everything a customer stores with us as confidential.
Q040Do you apply data protection by design and by default? (DSP-07)PartialWPMavenPartial. After your website is first built, no post goes out, no page is published and the team makes no change to your live website until you approve it. Visitor statistics on the websites we host use visitor identifiers hashed with a key that changes every day, and a visitor’s approximate location is worked out on our own servers without sending the address to anyone else. The tokens of the accounts you connect are encrypted a second time. We have no written privacy by design procedure.
Q041Have you carried out a data protection impact assessment (DPIA)? (DSP-09)NoWPMavenNo. We have not carried out a data protection impact assessment. Our Data Processing Agreement and this answer set give you the information you need for your own.
Q042Is personal data transferred outside the European Economic Area, and under what safeguards? (DSP-10)PartialWPMavenPartial. Some processing happens outside the EU: AI generation, email delivery, video clip generation and domain registration in the United States; the edge network worldwide; payments on Stripe; WhatsApp messages on WhatsApp’s own infrastructure; and our staff alert mailboxes in the United States. Our subprocessor page lists the safeguard for each company, which in most cases is the European Commission’s Standard Contractual Clauses in the company’s data processing terms; for one company it is not yet confirmed. We have not yet written transfer impact assessments.
Q043Can you help us answer data subject requests (access, correction, deletion, portability)? (DSP-11)YesSharedYes. You can correct, export and delete the content, contacts and orders in your WordPress site yourself, and disconnect any connected account, which deletes its stored tokens at once. For anything else, write to privacy@wpmaven.ai; we answer within 30 days, as our Privacy Policy states, and we pass on to you any request we receive about your data.
Q044Is personal data used only for the purpose of providing the service? (DSP-12)PartialWPMavenPartial. We process your data to provide WPMaven to you. One exception is stated in our Privacy Policy: our team reads the business descriptions people type, to improve how WPMaven understands requests, and keeps them until you ask us to erase them.
Q045Is customer data used to train AI models, by you or by your subprocessors? (DSP-12)PartialSharedPartial. We do not train AI models on your data. The provider that turns still images into short video clips receives the images and instructions for each clip; its terms let it use de-identified data to improve its services and contain no commitment against training. We are confirming which terms of our main AI provider apply to our account, and will state them here once confirmed; ask us for the current position.
Q046Are your subprocessors bound by data protection terms at least as protective as yours? (DSP-13)PartialWPMavenPartial. Our subprocessors work under their own standard data processing terms, which we have not negotiated individually. For one of them, the domain registrar, the data processing terms that apply are not yet confirmed.
Q047Do you disclose your subprocessors and notify customers of changes? (DSP-14)YesWPMavenYes. Every company that processes personal data for WPMaven is listed, with what it does and where, at wpmaven.ai/subprocessors.html. Customers who sign our Data Processing Agreement are told by email at least 30 days before we add or replace one, and can object.
Q048Do you keep production data out of development and test environments? (DSP-15)PartialWPMavenPartial. Our automated tests run on made-up data. We have no written rule that forbids copying production data into development.
Q049How do you handle sensitive data such as payment cards or health data? (DSP-17)PartialSharedPartial. WPMaven is not designed for health records or card data. Card payments run on Stripe’s own pages and never reach us. What you write is sent to our AI provider as written, so our Privacy Policy asks you to keep card numbers, passwords and health details out of it; we cannot filter them out for you.
Q050Will you tell us if an authority asks for our data? (DSP-18)YesWPMavenYes. Under our Data Processing Agreement (clause 3.1), if the law requires us to process your data other than on your instructions, we tell you first, unless the law forbids it.
Q051Can you tell us where customer data is stored and processed? (DSP-19)YesWPMavenYes. Stored in the European Union (Belgium): the application, its database, the websites we host, file storage and backups. Processed outside the EU: AI generation and video clip generation (United States), email delivery (United States), the edge network that delivers websites and forwards email (worldwide), payments (Stripe), WhatsApp messages (WhatsApp’s infrastructure), domain registration (United States) and staff alert emails (United States). Operational logs are kept by our cloud provider’s logging service, which is not tied to the EU region. Every company and location is on our subprocessor page.
Q052Can all processing be kept inside the European Union? (DSP-19)NoWPMavenNo. AI generation, email delivery, the edge network and the other services listed above run partly or wholly outside the EU, and we do not offer an EU-only option today.

Governance, risk and compliance

IDQuestionAnswerOwnershipDetail
Q053Do you have a documented information security program and management system? (GRC-05)NoWPMavenNo. We do not have a formal information security management system or written security policies. Our security practices are described in this answer set and recorded in our engineering records.
Q054Do you run a risk management program? (GRC-02)PartialWPMavenPartial. Each structured review assesses risk and ranks findings by the harm an attacker could do: money loss, data loss or account takeover. We have no formal risk register or annual risk assessment.
Q055Are security policies reviewed at least once a year? (GRC-03)NoWPMavenNo. We have no written security policies to review yet.
Q056Is someone accountable for security and data protection? (GRC-06)YesWPMavenYes. The founder and chief executive of Yotako S.A., the company that operates WPMaven, is accountable for security and data protection. Data protection questions go to privacy@wpmaven.ai or dpo@wpmaven.ai.
Q057Which laws and regulations apply to your processing, and who is your supervisory authority? (GRC-07)YesWPMavenYes. We operate under the GDPR and Luxembourg data protection law, and our supervisory authority is the Commission Nationale pour la Protection des Données (CNPD) in Luxembourg. Our Terms and Privacy Policy also address EU consumer law and the California Consumer Privacy Act.

Human resources

IDQuestionAnswerOwnershipDetail
Q058Do you run background checks on staff? (HRS-01)NoWPMavenNo. We do not run background checks on staff.
Q059Do you have an acceptable use policy for staff? (HRS-02)NoWPMavenNo. We have no written acceptable use policy for staff.
Q060Do you have a remote working security policy? (HRS-04)NoWPMavenNo. We have no written remote working policy. Our team works remotely; access to customer accounts goes through staff accounts and our staff console, described under identity and access management.
Q061Is access removed promptly when someone leaves? (HRS-06)PartialWPMavenPartial. Customer accounts can be opened only from staff accounts, and four named people hold administrative roles across our two cloud projects. Removing someone means clearing their staff flag, taking them off the staff list in our production configuration and removing their cloud roles. We have no written offboarding checklist.
Q062Are confidentiality agreement requirements documented and reviewed at planned intervals? (HRS-10)NoWPMavenNo. We have no documented confidentiality agreement requirements and no scheduled review of them.
Q063Do staff receive security and privacy awareness training? (HRS-11)NoWPMavenNo. We have no formal security or privacy awareness training program.

Identity and access management

IDQuestionAnswerOwnershipDetail
Q064Do you have a documented identity and access management policy? (IAM-01)NoWPMavenNo. We have no written access control policy. The controls in this section are how access works today.
Q065How do customers authenticate, and how are their credentials protected? (IAM-02)YesWPMavenYes. WPMaven has no customer passwords. You sign in with a 6-digit one-time code that we email you. It is valid for 10 minutes, stored only as a bcrypt hash, locked after 5 wrong attempts, and cancels any earlier code. Code requests are limited per email address and per IP address.
Q066Do you offer multi-factor authentication or single sign-on for customer accounts? (IAM-14)NoWPMavenNo. Beyond the one-time code sent to your email inbox, we do not offer a second factor, and we do not offer single sign-on yet.
Q067Is multi-factor authentication enforced for staff and administrative access? (IAM-14)NoWPMavenNo. We do not enforce a second factor on staff accounts through a central policy; our cloud projects are not part of a managed organization that could enforce one. What limits the risk: few people hold administrative roles (three in the project that runs the application, four across our two projects), our application runs under a narrow service identity, administrative activity is logged in both projects, and data access is logged too in the project that runs the application.
Q068Does every user have a unique identity, with no shared or generic accounts? (IAM-13)PartialWPMavenPartial. Every customer and every staff member signs in with their own identity. One temporary exception, an account used only for the social networks’ app reviews, will be removed when those reviews end; details under NDA on request.
Q069Do services and people have only the access they need? (IAM-05)PartialWPMavenPartial. Our application runs under a service identity with a custom role limited to the 31 server operations it performs, and our website servers can write only to backup storage and to logs. Some other service identities still hold broader rights than they need; narrowing them is an open item from our September review, details under NDA on request.
Q070Is staff access to customer data granted through a controlled process? (IAM-06)PartialWPMavenPartial. Customer accounts can be opened only from staff accounts. Addresses on a named list in our production configuration become staff accounts when they sign in, and staff can also mark another account as staff; that change is not yet recorded in our audit log. There is no ticketed approval workflow.
Q071Do you review user and administrator access on a schedule? (IAM-08)NoWPMavenNo. We do not run scheduled access reviews. The lists are short: a few staff accounts can open customer accounts, and four named people hold administrative roles across our two cloud projects.
Q072How is staff access to a customer account limited and recorded? (IAM-10)PartialWPMavenPartial. Customer accounts can be opened only from staff accounts. Each staff session in a customer account lasts at most 60 minutes, and its start and every change made through WPMaven during it are recorded under the staff member’s own name. During such a session the account’s sign-in details, billing, stored credentials and deletion cannot be changed, and another staff account cannot be opened. If staff open your WordPress admin, they use their own named WordPress administrator account, which loses its access 12 hours after they last used a sign-in link, unless it is the only administrator the site has. Changes made inside WordPress are not in our audit log, and some administrative changes staff can make outside such a session are not yet recorded.
Q073Is access to data authorized on every request? (IAM-16)YesWPMavenYes. Every request is checked against the owner of the account, business and site it touches, so a customer can reach only their own data. These ownership checks are covered by automated tests.
Q074How are sessions managed and revoked? (IAM-16)PartialWPMavenPartial. Sessions are signed tokens. A new session ends after 7 days without use and is renewed while you use WPMaven. Signing out ends the session on that device; it does not yet end your sessions on other devices. One internal hardening item on session expiry is open; details under NDA on request.
Q075Can a customer account have several users with different roles? (IAM-09)NoWPMavenNo. Each account has one login today. Team roles, per-business approvers and single sign-on are not available yet.

Interoperability and portability

IDQuestionAnswerOwnershipDetail
Q076Can customers export their data, and in what format? (IPY-04)YesSharedYes. Every site is standard WordPress. From WPMaven you can open your site’s WordPress admin, where WordPress’s own export tool and any WordPress backup or migration plugin can take a copy of the site. When a subscription ends, the site is taken offline and its final backup is kept for at least 90 days. There is no single download button for your account data in the dashboard yet; ask privacy@wpmaven.ai for a machine-readable copy.

Infrastructure and virtualization security

IDQuestionAnswerOwnershipDetail
Q077How are customers isolated from each other? (IVS-06)YesWPMavenYes. Each hosted website runs in its own container with its own limits on memory, processor time and number of processes, and with its own database user that can reach only its own database. Containers drop all Linux capabilities except the six WordPress needs to run (file ownership and permissions, switching users, binding its web port), cannot gain new privileges, and cannot reach the cloud metadata service or our server management agent. Sites share a server and a private network with the database server; the per-site database user is what keeps their data apart. In the application, every request is checked against the owner of the account, business and site it touches.
Q078How is the network protected? (IVS-03)PartialSharedPartial. Hosted websites are served through our edge network, and each website server accepts web traffic over TLS with a certificate issued for that edge. The application database accepts connections only through the cloud provider’s authenticated connector. One internal network hardening item is open; details under NDA on request.
Q079Do you protect against denial-of-service attacks and intrusions? (IVS-09)PartialSharedPartial. Hosted websites sit behind an edge network that absorbs denial-of-service attacks and caches pages, and the application API applies rate limits per user and per IP address. We run no intrusion detection system.
Q080Are servers hardened against a baseline? (IVS-04)PartialWPMavenPartial. Our website servers are built from one versioned server image and run only our own container images, with the container restrictions described above. We do not benchmark them against a published hardening standard such as the CIS Benchmarks.
Q081Are production and non-production environments separated? (IVS-05)PartialWPMavenPartial. Our automated tests run in the pipeline and on developers’ machines, apart from production. We have no staging environment that mirrors production.
Q082How do you plan capacity? (IVS-02)PartialWPMavenPartial. Website servers are added automatically as the number of hosted sites grows. The application itself runs as a single instance today by design, with room to scale up the instance; running several instances needs changes we have not made yet.
Q083Is your infrastructure architecture documented? (IVS-08)YesWPMavenYes. The edge network, website servers, application and database setup are documented in our infrastructure repository.

Logging and monitoring

IDQuestionAnswerOwnershipDetail
Q084Do you have a documented logging and monitoring policy? (LOG-01)NoWPMavenNo. We have no written logging policy. What we log and keep is described in this section.
Q085What security-relevant events do you log? (LOG-07)YesWPMavenYes. We log application events and requests, every action the AI team takes on a site (with its effect and, where possible, how to undo it), every approval, and each staff visit to a customer account with every change made through WPMaven during it; changes made inside a site’s WordPress admin are not in this log. The cloud project that runs the application records administrative activity and data access for all services; our second cloud project, which runs our public website and our analytics tool, records administrative activity.
Q086Are sign-ins and failed sign-in attempts logged? (LOG-12)YesWPMavenYes. Each sign-in code request is stored with the requesting IP address, and codes locked after too many wrong attempts are logged.
Q087How long are logs kept, and how are they protected? (LOG-09)PartialSharedPartial. Logs are kept by our cloud provider’s logging service: application logs, and data access logs where they are turned on, for 30 days, and administrative activity logs for 400 days in a store that cannot be shortened. Access to logs is limited to the people and services that administer our cloud projects. Logs are not copied to a separate archive. The action and approval records we keep in our database stay for the life of the account.
Q088Do you monitor for security events and alert on them? (LOG-03)PartialWPMavenPartial. Failures and unusual events raise alerts that are emailed to named staff and listed in our staff console. We run no security information and event management system, no intrusion detection and no around-the-clock monitoring.
Q089Are system clocks synchronized to a reliable time source? (LOG-06)YesCloud providerYes. Our servers and managed services use our cloud provider’s time synchronization.
Q090Can customers view or export an audit log of activity in their account? (LOG-04)NoWPMavenNo. There is no audit log view or export for customers yet.

Security incident management

IDQuestionAnswerOwnershipDetail
Q091Do you have a documented incident response plan? (SEF-03)NoWPMavenNo. We have no written incident response plan yet. Today, failures alert named staff, and a personal data breach is handled under the notification commitments below.
Q092Is the incident response plan tested? (SEF-04)NoWPMavenNo. We have no written plan to test yet.
Q093Will you notify us of a personal data breach, and how quickly? (SEF-07)YesWPMavenYes. Our Privacy Policy commits us to tell you within 72 hours of discovering a breach that affects your personal data. Under our Data Processing Agreement, business customers are told without undue delay and within 48 hours of our becoming aware of a breach affecting the data we process for them. We notify the data protection authority where the law requires.
Q094How can someone report a security vulnerability? (SEF-08)YesWPMavenYes. Write to support@wpmaven.ai with enough detail to reproduce the problem. We read every report, tell the reporter what we found, and take no action against good-faith research. We do not run a bug bounty.

Supply chain management and transparency

IDQuestionAnswerOwnershipDetail
Q095Do you document which security responsibilities are yours and which are the customer’s? (STA-04)PartialSharedPartial. Our Terms, our Data Processing Agreement and this answer set say what we are responsible for and what you are responsible for; for example, you review what you approve and you keep your own website’s privacy notice current. The ownership column of this answer set shows who operates each control. We have not published a separate shared responsibility matrix.
Q096Do you keep an inventory of the suppliers that process customer data? (STA-07)YesWPMavenYes. Every company that processes personal data for WPMaven is listed at wpmaven.ai/subprocessors.html with what it does, what it sees and where.
Q097Do you assess the security of your suppliers? (STA-08)NoWPMavenNo. We do not run formal security assessments of our suppliers. We use established providers and rely on their published independent audits where they have them.
Q098Do your supplier contracts include security and data protection terms? (STA-09)PartialWPMavenPartial. Our subprocessors work under their standard data processing terms, which include security commitments. We have not negotiated individual terms, and for the domain registrar the applicable data processing terms are not yet confirmed.
Q099Is the software you ship to customer websites signed and verified? (STA-14)YesWPMavenYes. Updates of our WordPress plugin are signed, and the plugin checks the signature before it installs an update and refuses one that is unsigned or altered.
Q100How do you manage third-party code and open-source dependencies? (STA-14)PartialWPMavenPartial. Our dependencies are pinned by lock files and installed reproducibly in our pipelines. We do not scan them automatically for known vulnerabilities. One internal hardening item on third-party code is open; details under NDA on request.

Threat and vulnerability management

IDQuestionAnswerOwnershipDetail
Q101Do you have a documented vulnerability management policy? (TVM-01)NoWPMavenNo. We have no written vulnerability management policy.
Q102Do you commission independent penetration tests? (TVM-06)NoWPMavenNo. No outside company has tested our security yet. Our security reviews so far are our own.
Q103Do you run automated vulnerability scans of your applications and infrastructure? (TVM-07)NoWPMavenNo. We do not run automated vulnerability scans. We find issues through structured internal reviews of our code and infrastructure.
Q104Do you monitor third-party libraries for known vulnerabilities? (TVM-05)NoWPMavenNo. We do not run automated dependency vulnerability monitoring. We update dependencies as part of normal development.
Q105Do you have defined time frames to fix vulnerabilities by severity? (TVM-03)PartialWPMavenPartial. We fix by severity: anything that could lead to account takeover, data exposure or money loss is fixed before release. We have no written deadlines per severity.
Q106How are the websites you host kept patched? (TVM-04)PartialSharedPartial. WordPress’s own automatic security updates are left on for every site we host, and our WordPress plugin updates itself automatically with signed releases. Updates to other plugins and themes are applied from each site’s WordPress admin.
Q107Do you run anti-malware protection on your servers? (TVM-02)NoWPMavenNo. We do not run anti-malware software on our servers. They run only our own container images, and site containers are restricted as described under infrastructure security.

Endpoint management

IDQuestionAnswerOwnershipDetail
Q108Are staff laptops centrally managed (policy, anti-malware, remote wipe)? (UEM-05)NoWPMavenNo. We have no written endpoint policy and no central management of staff devices.
Q109Is disk encryption enforced on staff devices? (UEM-08)NoWPMavenNo. We do not enforce disk encryption on staff devices centrally.

Questions this page does not answer

Write to legal@wpmaven.ai with your own questionnaire. If we cannot answer something yet, we will say so.