0769755be99178421a2332cfd3cfeb9bd09ae50d478d475d266f7c1e8a3284bd
active
contextual
prescribed

For critical vendors without a SOC 2 report that access PYRANA.ai data or affect system security, a quarterly vendor risk assessment must be performed so that these higher-risk vendors receive compensating oversight.

Supporting contexts

Quoteverbatim

For critical vendors that do not have a SOC 2 report

Pyrana Vendor Management Policy.pdf

Quoteverbatim

but that have access to PYRANA.ai data or that impact the security of PYRANA.ai system

Pyrana Vendor Management Policy.pdf

Quoteverbatim

a quarterly vendor risk assessment is performed

Pyrana Vendor Management Policy.pdf

Effective from: 7/16/2026, 10:38:48 PM

History