E-001 · Internal
Architecture Standard v2.1
Owner: Platform Lead
Last reviewed: 14 April 2026
Next review: 14 October 2026
Fictional demonstration
NimbusFlow is not a real company. Every name, answer, document, metric, and gap below exists only to demonstrate the delivery structure.
The review is ready for internal approval, not external submission. Two claims remain blocked because the fictional source set does not support them.
The four rows below are a status-diverse excerpt from the fictional 12-question review, not the complete answer library.
| Topic | Canonical answer | Status | Evidence | Owner | Review |
|---|---|---|---|---|---|
| Encryption in transit | TLS 1.2 or higher is required for customer-facing production traffic. | Approved | Architecture Standard v2.1 §4.2 | Platform Lead | Oct 2026 |
| Privileged access | Administrative access is role-based, requires MFA, and is reviewed quarterly. | Needs owner | Access Policy v1.4; Q2 review record missing | Security Lead | Now |
| Incident notification | Customer notification follows contract terms after impact and scope are established. | Approved | Incident Plan v3.0 §7; DPA §9 | Legal + Security | Jan 2027 |
| Annual penetration test | No current third-party penetration-test report is available. | Gap | Evidence search completed; none found | CTO | Open |
E-001 · Internal
Owner: Platform Lead
Last reviewed: 14 April 2026
Next review: 14 October 2026
E-002 · Restricted
Owner: Security Lead
Last reviewed: 7 January 2026
Next review: 7 July 2026
E-003 · Confidential
Owner: Security Lead
Last reviewed: 21 March 2026
Next review: 21 September 2026
Buyer impact: likely blocker for production-data access. Interim answer: state the absence; do not imply a test is scheduled. Next action: CTO decides whether the opportunity justifies an independent test.
Buyer impact: control exists in policy but operating evidence is incomplete. Next action: Security Lead completes and approves the review before changing the answer status.