OpsRabbit Trust Center

Customer Audit and Assurance Policy

A proportionate, evidence-first approach to security assurance.

PublicVersion 1.0September 2026

Overview

This policy describes how customers can evaluate OpsRabbit security without exposing sensitive implementation details or disrupting operations. Public documents are the starting point; additional evidence is released in proportion to the request and applicable agreement.

The sections below explain available evidence, review stages, audit conditions, restricted material and remediation follow-up.

Evidence-first assurance

OpsRabbit provider responds to reasonable customer security reviews using current policies, architecture summaries, testing evidence, questionnaires and certifications available for the applicable scope. Public summaries should be used first; sensitive evidence is shared through a controlled process.

Available evidence

  • Responsible AI Policy and AI Governance Framework
  • Security Overview, data-flow documentation and shared-responsibility matrix
  • Customer-safe VAPT completion evidence
  • Incident-response and continuity summaries
  • Current certification status and scope statements

Audit conditions

If standard evidence is insufficient for obligations under an executed DPA, an audit request should be limited to relevant systems and processing, use qualified independent personnel, preserve confidentiality, avoid unreasonable operational disruption, and normally occur no more than once annually unless a material incident or regulator requires otherwise. Commercial and cost terms are governed by the agreement.

Standard assurance sequence

  1. Use public Trust Center materials and current certificates.
  2. Submit a scoped questionnaire identifying the customer requirement.
  3. Request controlled evidence for gaps not addressed by public material.
  4. If contractual and still insufficient, request a focused independent audit.

This sequence protects customer assurance needs without exposing other customers’ data, source code, exploit details, personal information or privileged security architecture.

Request requirements

An audit request must identify the legal or contractual basis, control objective, systems and period in scope, proposed dates, auditor identity, evidence needed and confidentiality protections. Auditors must be suitably qualified and independent and may not be an OpsRabbit competitor. Reviews occur during reasonable business hours and must avoid disruption.

Frequency, cost and findings

Routine customer audits are normally limited to once in a twelve-month period. Additional review may be appropriate following a confirmed material incident, a regulator’s binding request, or documented evidence of material non-compliance. Unless the agreement states otherwise, the customer bears its audit costs. Findings must be disclosed promptly to OpsRabbit provider and handled confidentially; remediation timing is based on validated risk.

Restricted evidence

Raw penetration-test reports, source code, credentials, infrastructure identifiers, detailed network diagrams, employee records, other-customer information and active defensive configurations are not public. OpsRabbit provider may provide a summary, redacted extract, independent report or live review instead.