> ## Documentation Index
> Fetch the complete documentation index at: https://doc.entelligence.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Procurement and security FAQ

> Questions to resolve for Entelligence plans, deployment, security, privacy, identity, reliability, support, model providers, and exit planning.

Use this checklist with Entelligence's security and commercial teams. Do not treat a dashboard label or public marketing statement as a contractual commitment.

## Evidence already available

| Item            | Current evidence                                                              | What to request                                                                         |
| --------------- | ----------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| SOC 2           | The public homepage states SOC 2 Type II                                      | Current report, scope, period, exceptions, remediation, and bridge letter               |
| Privacy         | A public privacy policy describes personal-data processing and U.S. transfers | DPA, subprocessors, product-specific retention, deletion, and residency terms           |
| Workspace roles | The app exposes Member and Admin                                              | Task-level permission matrix and enterprise identity behavior                           |
| SSO/SCIM        | Not exposed in the audited self-service settings                              | Supported plans, IdPs, enforcement, provisioning, audit events, and break-glass process |
| Deployment      | The audited app is hosted and has no deployment selector                      | Purchased architecture, responsibility matrix, regions, recovery, and support           |
| Connectors      | The catalog shows available and coming-soon integrations                      | Entitlement, scopes, data fields, write actions, limits, and support status             |

## Commercial

* Which products and connectors are included?
* How are seats, tokens, overages, Model Router balance, and provider charges measured?
* What are invoice, renewal, refund, and credit-expiry terms?
* Which usage limits apply?
* What happens when a limit is reached?

## Security and privacy

* Which certifications and reports are current?
* Which subprocessors and model providers are used?
* Are customer inputs or outputs used for training?
* What are product-specific retention and deletion periods?
* Which processing regions and transfers apply?
* How are secrets encrypted, accessed, and rotated?
* How is tenant isolation tested?
* What support and debugging access exists?
* Which penetration-testing rules apply?

## Identity and audit

* Are SSO/SAML, SCIM, MFA, and domain enforcement included?
* Which roles and task permissions exist?
* Which actions are audited?
* Can audit events be exported to a SIEM?
* How long are audit events retained?
* How are sessions revoked?

## Reliability and support

* Availability commitment
* Support hours and severity definitions
* Backup and recovery objectives
* Incident-notification timeline
* Status page and escalation path
* Change and maintenance windows
* Hosted and customer responsibility split

## Exit

* Export formats and assistance
* Data-deletion process and evidence
* Connector and credential revocation
* Historical analytics behavior
* Backup expiry
* Account closure and final invoice

## Next step

Build the rollout plan with the [administrator checklist](/get-started/admin-checklist) and retain approved answers with the security review.
