Answering Your Own Security Assessment: When and How to Use Our Security Documentation

Prev Next

We maintain a detailed, regularly updated set of security documentation covering our controls and audits. Most vendor risk and security questionnaires can be answered directly from these materials, so you don't have to wait on a manual response from our team.

This article explains when to use the documentation, how to use it, and how to reach us if you need more.

Step 1: Check the Documentation First

Before submitting a request, review our resources here: Security Assessments and Questionnaire:

  • Standard Response Questionnaire: A comprehensive overview of our security program, covering areas such as access control, privacy, operational resilience, third-party risk, and artificial intelligence.

  • Standard Cloud Security Assessment: Our approach to securing our cloud environment and hosting infrastructure.

  • SOC 2 Type II Report + Bridge Letter: Independent audit results and coverage for the period since the report was issued.

Step 2: Use the Documents to Complete Your Questionnaire

These resources are a good fit if your questionnaire requires any of the following:

  • General security posture answers

  • Cloud security or hosting-related answers

  • A standardized security questionnaire format

  • Reference material for your own custom questionnaire (most of the answers you need are already included)

Step 3: Reach Out If You Need Something More

We're always happy to help! If your questionnaire asks for something our documents don't cover, such as changes since your last review, send us a note at securityassessment@Ripple Treasury.com and we'll take it from there.

Checking the documentation first is the quickest way to get your answers, and it lets our team focus on the requests that need a more tailored response.

What to Include in Your Email

To help us get you what you need as quickly as possible, please include:

  1. What's missing and why: Describe the information you need and why our documents don't cover it.

  2. Scope or framework needed: For example, NIST or ISO 27001.

  3. Due date: Our standard turnaround time is 4 weeks, so please provide a due date that allows for at least that much time.

  4. Portal or document format: If your questionnaire is in a portal, include the portal name, URL, and credentials (username: securityassessment@Ripple Treasury.com).

Quick Reference

If you need...

Do this

General security posture answers

Use the Standard Response Questionnaire

Cloud security or hosting details

Use the Standard Cloud Security Assessment

Audit or compliance evidence

Use the SOC 2 Type II Report + Bridge Letter

Something not covered in the documents

Email securityassessment@Ripple Treasury.com with the details above