0769755be99178421a2332cfd3cfeb9bd09ae50d478d475d266f7c1e8a3284bd
active
contextual
prescribed
For critical vendors without a SOC 2 report that access PYRANA.ai data or affect system security, a quarterly vendor risk assessment must be performed so that these higher-risk vendors receive compensating oversight.
Supporting contexts
Quoteverbatim
For critical vendors that do not have a SOC 2 report
— Pyrana Vendor Management Policy.pdf
Quoteverbatim
but that have access to PYRANA.ai data or that impact the security of PYRANA.ai system
— Pyrana Vendor Management Policy.pdf
Quoteverbatim
a quarterly vendor risk assessment is performed
— Pyrana Vendor Management Policy.pdf
Effective from: 7/16/2026, 10:38:48 PM