Procurement · vendor review

Everything a vendor review asks for.

On one page, so you do not have to ask us for it one document at a time.

The company

Legal entityFalsify OÜ, registry code 17574308, Estonia
Independently verifiable atariregister.rik.ee
Registered officeNarva mnt 5, 10117 Tallinn
Full details and continuity/legal

The documents

Privacy and data handling/privacy
Subprocessors/subprocessors
Terms/terms
Security policy and reporting/security
Data processing agreementOn request, before any engagement starts
Pricing and scope/pricing, fixed price by scope, no bands
What a deliverable looks likea worked Evidence Pack, with real hashes you can check

Current assurance posture

SOC 2 / ISO 27001Not held. Security practices are documented on the security page; the deliverable itself verifies offline and does not depend on our infrastructure.
SSO / SAMLNot offered. The registry requires no accounts; there is nothing to sign into.
SLANo formal SLA. Verification is offline against artefacts you hold, so registry availability does not gate your evidence.
Penetration testNo third-party report held. An independent review of the commitment primitive is being scoped.

If one of these is a hard requirement for your review, this page is intended to answer that early.

Two things that reduce your risk more than a badge would

Anything missing from this page, write to [email protected] and we will add it here rather than send it to you privately.

If you are writing the requirement rather than answering it, the clause and the gate it belongs to are set out on the require page, along with the four bodies that already ask for criteria to be fixed before results are known.