This policy establishes how Northwind AI governs the controls described below. It exists to protect Northwind AI's systems, data, and customers, and to satisfy the obligations of SOC 2 and NIS2.
This policy applies to all Northwind AI personnel, contractors, systems, and third parties that process Northwind AI data. It maps to the requirements of SOC 2 and NIS2 and is reviewed at least annually or on material change.
Northwind AI maintains documented, enforced controls for the area covered by this policy. Each control is monitored continuously, evidence is collected automatically where possible, and exceptions are tracked, justified, and time-bound. Where a control carries regulatory or contractual liability, a credentialed reviewer co-signs it before it is treated as met.
The security owner maintains this policy and the underlying controls. System owners implement and evidence the controls in their area. All personnel are responsible for adhering to this policy. A credentialed reviewer (e.g. CISSP, CIPP/E, or lead auditor) co-signs high-judgment controls.
Violations are handled under Northwind AI's disciplinary process. This policy is owned by the security function, approved by management, and reviewed at least annually. The current readiness of the controls it governs is visible in the Attestloop console and on the published Trust Page.