Fictional demonstration

NimbusFlow security review pack

NimbusFlow is not a real company. Every name, answer, document, metric, and gap below exists only to demonstrate the delivery structure.

Not assurance: this sample is not evidence of any real control or compliance status.

Review summary

12sample questions
7approved
3owner inputs
2gaps

The review is ready for internal approval, not external submission. Two claims remain blocked because the fictional source set does not support them.

Answer library by status

The four rows below are a status-diverse excerpt from the fictional 12-question review, not the complete answer library.

TopicCanonical answerStatusEvidenceOwnerReview
Encryption in transitTLS 1.2 or higher is required for customer-facing production traffic.ApprovedArchitecture Standard v2.1 §4.2Platform LeadOct 2026
Privileged accessAdministrative access is role-based, requires MFA, and is reviewed quarterly.Needs ownerAccess Policy v1.4; Q2 review record missingSecurity LeadNow
Incident notificationCustomer notification follows contract terms after impact and scope are established.ApprovedIncident Plan v3.0 §7; DPA §9Legal + SecurityJan 2027
Annual penetration testNo current third-party penetration-test report is available.GapEvidence search completed; none foundCTOOpen

Evidence freshness register

E-001 · Internal

Architecture Standard v2.1

Owner: Platform Lead
Last reviewed: 14 April 2026
Next review: 14 October 2026

Current

E-002 · Restricted

Access Policy v1.4

Owner: Security Lead
Last reviewed: 7 January 2026
Next review: 7 July 2026

Review due

E-003 · Confidential

Incident Plan v3.0

Owner: Security Lead
Last reviewed: 21 March 2026
Next review: 21 September 2026

Current

Honest gap queue

High

Current penetration-test evidence is missing

Buyer impact: likely blocker for production-data access. Interim answer: state the absence; do not imply a test is scheduled. Next action: CTO decides whether the opportunity justifies an independent test.

Medium

Quarterly privileged-access review lacks a Q2 record

Buyer impact: control exists in policy but operating evidence is incomplete. Next action: Security Lead completes and approves the review before changing the answer status.

What this structure prevents