| c9288729fc63fc35… | PYRANA.ai must take corrective actions based on assessment results when vendor assessments identify issues so that identified risks or deficiencies are addressed appropriately. | active | contextual | yes | |
| 180a510f0a3b8a51… | For critical vendors without a SOC 2 report that have access to PYRANA.ai data or affect PYRANA.ai system security, PYRANA.ai performs a vendor risk assessment quarterly so that vendor risk, performance, service delivery, and security compliance are evaluated regularly. | active | contextual | yes | |
| 9bd83fca84ef64cc… | The document is identified as Version 2 so that the specific revision of the vendor management policy can be referenced and controlled. | active | contextual | yes | |
| 490a79d5d89a2f28… | The vendor management policy document was approved on 03/10/2026 so that the approval date of the policy version is explicitly recorded. | active | contextual | yes | |
| 0f48b670a26f3b19… | Eric Tarnowski is identified as the Secondary Signatory for this vendor management policy approval so that the document records the secondary approving signatory. | active | contextual | yes | |
| 4fa97a521f409aad… | James Canterbury is identified as the Primary Signatory for this vendor management policy approval so that the document records the primary approving signatory. | active | contextual | yes | |
| 938e216c25a6be31… | PYRANA.ai performs exit reviews on vendors to ensure compliance with termination clauses so that vendor offboarding is verified against contractual termination requirements. | active | contextual | yes | |
| 187ba17f43772dcf… | PYRANA.ai must agree on appropriate provisions with vendors to ensure continued security of information and systems if a contract is terminated or transferred to another supplier so that security is maintained during transition or exit events. | active | contextual | yes | |
| 95332ae50d7234d9… | Procurement and contract managers designated by PYRANA.ai management must immediately ensure termination of a vendor’s access to PYRANA.ai systems and, if applicable, facilities housing those systems so that access is promptly cut off after termination. | active | contextual | yes | |
| 6fb5815a753f1883… | Upon termination of vendor services, contracts must require the return or destruction of all organization data unless otherwise agreed so that organizational information is not retained without authorization after service termination. | active | contextual | yes | |
| 65c1624325f091cd… | When a vendor or service provider relationship is terminated, access is removed through a termination checklist and revoked as part of the termination process so that former vendors no longer retain authorized access. | active | contextual | yes | |
| 68773522a6d37d41… | PYRANA.ai includes clauses in agreements with vendors and service providers that allow termination of relationships when necessary so that the organization can formally end vendor engagements under appropriate circumstances. | active | contextual | yes | |
| 89048b427d6c1d55… | PYRANA.ai takes corrective actions as required based on the results of vendor assessments so that identified issues are addressed after assessment findings are reviewed. | active | contextual | yes | |
| 82d3150457ce8cd3… | During the quarterly assessment for certain critical vendors, PYRANA.ai assesses performance, service delivery, and compliance with security commitments so that operational and security obligations are reviewed together. | active | contextual | yes | |
| aacbb7d8a2eb9b32… | For critical vendors that do not have a SOC 2 report but have access to PYRANA.ai data or affect the security of the PYRANA.ai system, PYRANA.ai performs a quarterly vendor risk assessment so that vendor risk is regularly evaluated under heightened conditions. | active | contextual | yes | |
| 0b0732f6fc324c0f… | The document is identified as Version 2 so that readers can distinguish this policy revision from other versions. | active | contextual | yes | |
| 33e4b3d588f3229c… | The vendor management policy document was approved on 03/10/2026 so that the policy has a recorded approval date. | active | contextual | yes | |
| 50cb952fca615e05… | Eric Tarnowski is identified in the document as the Secondary Signatory so that the policy records an authorized secondary approver. | active | contextual | yes | |
| 76c223a2cc5d737a… | James Canterbury is identified in the document as the Primary Signatory so that the policy records an authorized primary approver. | active | contextual | yes | |
| c6f4b6fbd9b28675… | Exit reviews must be performed on vendors to verify compliance with termination clauses so that PYRANA.ai confirms vendors met contractual termination obligations. | active | contextual | yes | |
| db98e5e193389a7f… | PYRANA.ai must agree on appropriate provisions with vendors to maintain the security of information and systems if a contract is terminated or transferred to another supplier so that security continues during supplier transition. | active | contextual | yes | |
| 993c40d2380c9fc4… | Procurement and contract managers designated by PYRANA.ai management must immediately ensure termination of a vendor’s access to PYRANA.ai systems and, when applicable, facilities housing those systems so that access ends promptly after termination. | active | contextual | yes | |
| 4f374d7a2e4c5a2f… | Upon termination of vendor services, contracts must require the return or destruction of all organization data unless another arrangement is agreed so that organizational data is not retained improperly after service ends. | active | contextual | yes | |
| 36fab182ae9e7ce5… | When a vendor or service provider relationship is terminated, access is removed through a termination checklist and revoked as part of the termination process so that former vendors no longer retain access. | active | contextual | yes | |
| 6197f12bb00835de… | PYRANA.ai includes contractual clauses in agreements with vendors and service providers that allow termination of relationships when necessary so that the organization can formally end vendor engagements. | active | contextual | yes | |
| 80057cad80a7295d… | PYRANA.ai takes corrective actions when required based on assessment results so that identified vendor issues are addressed after review. | active | contextual | yes | |
| 8986f9a7663f05dd… | During the quarterly assessment of critical vendors without a SOC 2 report, PYRANA.ai assesses performance, service delivery, and compliance with security commitments so that vendor oversight includes operational and security factors. | active | contextual | yes | |
| 6410ec9a020ae7d1… | For critical vendors that lack a SOC 2 report but have access to PYRANA.ai data or affect the security of the PYRANA.ai system, PYRANA.ai performs a vendor risk assessment every quarter so that vendor risk is regularly evaluated. | active | contextual | yes | |
| af08778d34f67571… | When vendor services terminate, contracts must require return or destruction of all organization data unless otherwise agreed so that organizational information is not retained after the relationship ends. | active | contextual | yes | |
| 0ddb000e2108d1c7… | Upon vendor or service provider termination, access must be removed through a termination checklist and revoked as part of the termination process so that former vendors no longer retain system access. | active | contextual | yes | |
| 547394c7476cf137… | PYRANA.ai includes clauses in agreements with vendors and service providers that allow termination of relationships when necessary so that the organization can formally end problematic vendor engagements. | active | contextual | yes | |
| 623fad4af333cc76… | Corrective actions are taken as required based on assessment results so that identified vendor oversight issues are remediated. | active | contextual | yes | |
| e871201257793857… | During the quarterly assessment of critical vendors, performance, service delivery, and compliance with security commitments are also assessed so that operational and security adherence are monitored together. | active | contextual | yes | |
| 0769755be9917842… | For critical vendors without a SOC 2 report that access PYRANA.ai data or affect system security, a quarterly vendor risk assessment must be performed so that these higher-risk vendors receive compensating oversight. | active | contextual | yes | |
| 980ee83f7cb15c65… | At onboarding and annually thereafter, management performs reviews of service provider or vendor SOC 2 reports to evaluate scope appropriateness, the impact of identified exceptions, and applicable complementary user entity controls. | active | contextual | yes | |
| 56dd6bd34ce381a6… | During onboarding, vendor responsibilities, including security commitments and responsibilities, must be documented and agreed with the vendors so that obligations are clearly established at the start of the relationship. | active | contextual | yes | |
| 9be4dc555e757d65… | Vendor contracts must clearly identify security reporting requirements stating that the vendor is responsible for maintaining the security of confidential data regardless of ownership so that accountability for data protection is explicit. | active | contextual | yes | |
| 15843b4587e04565… | Contracts involving exchange of confidential data must require vendor confidentiality agreements and must identify the security policies and procedures applicable to the vendor so that confidentiality obligations are formally established. | active | contextual | yes | |
| eb7b228bebefbeb1… | During vendor onboarding, the vendor must sign the PYRANA.ai vendor contract, or if the vendor is an online service provider, PYRANA.ai must accept the vendor’s predefined terms of service so that the relationship is contractually established. | active | contextual | yes | |
| 9b8ab8c22a84ef66… | The vendor risk assessment process should consider due diligence factors such as distributed IT environments, legacy suppliers, and subcontractor use by the third party so that inherited operational and security risks are understood. | active | contextual | yes | |
| 15f3929b2a653a9f… | The vendor risk assessment process should consider regulatory requirements because regulators mandate supervision of third-party suppliers for security, privacy, and data protection compliance. | active | contextual | yes | |
| 1665601aa01b50d9… | The vendor risk assessment process should consider data exposure risks from incorrectly classified or unidentified data that could be exposed to a third party so that unintended disclosure is prevented. | active | contextual | yes | |
| e98849fce8270ca6… | The vendor risk assessment process should consider business continuity and service availability as third-party services become more integrated into the core company offering so that operational dependency risks are addressed. | active | contextual | yes | |
| 8e08210dd2aa551c… | The vendor risk assessment process should consider monitoring gaps, including periodic assessments, ongoing monitoring, incident notification, offboarding, adherence, and SLA appropriateness, so that oversight weaknesses are identified. | active | contextual | yes | |
| b88042f7115c3d0a… | The vendor risk assessment process should consider information security controls related to security, privacy, confidentiality, and availability of shared data so that third-party data protection risks are evaluated. | active | contextual | yes | |
| 120014c47ff77b56… | Upon termination of vendor services, contracts must require return or destruction of all organization data unless otherwise agreed so that organizational information is not retained after the relationship ends. | active | contextual | yes | |
| 61737c614e77a2d2… | When a vendor or service provider is terminated, access must be removed through a termination checklist and revoked as part of the termination process so that former third parties no longer retain access. | active | contextual | yes | |
| fb681a898078ded6… | PYRANA.ai includes termination clauses in agreements with vendors and service providers so that relationships can be ended when necessary. | active | contextual | yes | |
| aeee9f2fae309b41… | Corrective actions must be taken as required based on assessment results so that identified vendor oversight issues are remediated. | active | contextual | yes | |
| cc9f104fb4e5c230… | During quarterly assessments of critical vendors, management also evaluates service delivery performance and compliance with security commitments so that operational and security obligations are monitored together. | active | contextual | yes | |