Skip to content
Brocode SolutionsAI Software Development

Vendor due-diligence pack

The Vendor Security Pack. Same day, under NDA.

SOC 2 Type II, ISO/IEC 27001:2022, ISO 42001, a CREST-tested penetration summary, a UAE PDPL and GDPR-aligned DPA, and the live sub-processor register — assembled for your TPRM workflow. Median customer due-diligence: nine working days.

Last SOC 2 Type II

14 Mar 2026

Last ISO 27001 surveillance

08 Feb 2026

Last penetration test

04 Mar 2026

Open critical / high

0 / 0

Certifications mosaic

SOC 2 Type II
ISO 27001:2022
ISO 27701
ISO 42001
Cyber Essentials+
PCI-DSS v4
CSA STAR L2
TDRA IA
PDPL UAE
AWS Security
Microsoft Sec.
G42 Cloud

Crests rendered as monochrome marks. Licensee numbers and certificate PDFs are inside the Vendor Security Pack.

  • 9 days

    Median TPRM cycle to approval across last 22 engagements

  • 0 / 0

    Open critical / high findings — March 2026 pen test

  • 11

    Sub-processors, country-of-processing transparent

  • 24 hrs

    Customer notification SLA on confirmed incident

Inside the pack

Every artefact your TPRM analyst would otherwise chase across five emails.

A single zipped bundle, NDA-gated, with file sizes, last-updated dates, and gating notes against each document so procurement can route them to the right reviewer.

The headline file

SOC 2 Type II — 12 months ending 31 Dec 2025

Signed 14 March 2026 by a Big-4 affiliated CPA firm covering Security, Availability, Confidentiality, and Processing Integrity. Bridge letter included to today.

PDF, 8.4 MB — NDA-gated

Penetration test

Executive summary — pre-NDA

Full report under NDA. CREST-accredited tester. 0 open critical / high.

ISO 27001 + SOA

93 controls mapped, latest BSI surveillance letter included

PDF, 2.1 MB — NDA-gated

ISO 42001:2023

AI management system policy and scope statement

PDF, 1.4 MB — pre-NDA

DPA template

UAE PDPL + GDPR + DIFC DP Law aligned, EU SCCs 2021/914 pre-filled

DOCX, 380 KB — pre-NDA

Sub-processor register

11 sub-processors, country of processing, contractual safeguard

PDF, 240 KB — pre-NDA

CAIQ v4

Pre-filled Cloud Security Alliance questionnaire

XLSX, 410 KB — pre-NDA

BCP / DR summary

RTO 4h, RPO 15m, last DR test Q4 2025

PDF, 1.1 MB — NDA-gated

Incident response policy

Runbook summary, escalation tree, 24-hour customer notification

PDF, 720 KB — NDA-gated

Certifications & attestations

Twelve current marks, each with its last-audit date and next surveillance window.

Every entry below carries the licensee number on the certificate PDF inside the Vendor Security Pack. The scope, the issuing body, and the renewal cycle are documented so your TPRM analyst can verify with the registrar directly.

Certification / attestationIssuing bodyLast auditNext dueStatus
SOC 2 Type IIBig-4 affiliated CPA firm14 March 2026March 2027Current
ISO/IEC 27001:2022BSI08 February 2026February 2027Current
ISO/IEC 27701:2019BSI08 February 2026February 2027Current
ISO/IEC 42001:2023BSI21 January 2026January 2027Current
Cyber Essentials PlusIASME02 December 2025December 2026Current
PCI-DSS v4.0 AoCQSA — Coalfire11 November 2025November 2026Current
CSA STAR Level 2Cloud Security Alliance17 October 2025October 2026Current
AWS Security CompetencyAWS03 September 2025September 2026Current
Microsoft Solutions Partner — SecurityMicrosoft12 January 2026January 2027Current
G42 Cloud Certified PartnerG4228 February 2026February 2027Current
NVIDIA Inception (security-reviewed)NVIDIA04 March 2026March 2027Current
TDRA Information Assurance attestationTDRA — UAE19 November 2025November 2026Current

Framework cross-walk

One control set, mapped to the frameworks your risk function already speaks.

Each row pins a control function to its corresponding identifier in NIST CSF 2.0, ISO/IEC 27002:2022, NESA UAE IA, SAMA Cyber Security Framework, and ISO/IEC 42001. The full cross-walk Excel is in the Vendor Security Pack.

CapabilityBrocode postureNIST CSF 2.0ISO 27002:2022NESA UAE IASAMA CSFISO 42001 / SCF
Identify — asset and risk inventoryContinuous, registeredID.AM, ID.RAA.5.9, A.5.12T1.1, T1.2CSF 1.1.1IS-1, IS-2
Protect — access control + cryptoCustomer-managed keys defaultPR.AC, PR.DSA.5.15, A.8.24T3.1, T3.4CSF 2.2.1IS-12, IS-15
Detect — continuous monitoring24/7 SOC + SIEMDE.AE, DE.CMA.8.15, A.8.16T6.2, T6.3CSF 3.1.4IS-26
Respond — incident handling1-hour ack SLARS.RP, RS.ANA.5.24, A.5.26T9.1, T9.2CSF 4.1.1IS-30
Recover — BCP / DRRTO 4h, RPO 15mRC.RP, RC.IMA.5.29, A.5.30T10.1CSF 5.1.2IS-34
AI management systemISO 42001:2023CSF 2.0 — AI profileA.5.36 (Annex SL)NewNewAligned via mapping
Personal data protectionPDPL + GDPR alignedID.GV, PR.IPA.5.34T2.3CSF 1.4.2IS-9

Encryption & key management

Customer-managed keys are the default, not the premium tier.

Cryptographic posture aligned to ISO/IEC 27002:2022 control 8.24. Every key, every algorithm, every rotation cadence is in the cryptographic inventory inside the Vendor Security Pack.

BYOK on hyperscalers

AWS KMS (FIPS 140-2 L2 envelope), Azure Key Vault HSM (L3), Google Cloud KMS where requested. Keys originate from your tenancy; Brocode operates on grants. Quarterly rotation default; manual rotation on demand.

HYOK on UAE sovereign

Thales Luna Network HSM 7 (FIPS 140-2 L3) in the customer DC, or Khazna-hosted HSM cluster. Keys never leave the HSM boundary; envelope keys are wrapped under the customer KEK on every workload.

Algorithms and TLS

AES-256-GCM at rest, ChaCha20-Poly1305 for legacy clients, TLS 1.3 in transit (TLS 1.2 only where the customer estate mandates). RSA-2048 deprecated; ECDSA P-384 and Ed25519 for new keys. Post-quantum hybrid (X25519 + Kyber) under pilot.

Sub-processor register

Eleven sub-processors. Country of processing. Purpose. Contractual safeguard.

Reviewed monthly. Changes notified to customers 30 days in advance, with an objection window. Last full review: 02 May 2026.

Sub-processorCountry of processingPurposeSafeguard
Amazon Web Services EMEA SARLUAE — me-central-1 (Dubai)Sovereign hosting and storageDPA + SCCs (back-up)
Microsoft Ireland Operations LtdUAE — UAE NorthIdentity (Entra ID) and Microsoft 365DPA + SCCs (back-up)
G42 CloudUAE — KhaznaSovereign compute and GPUUAE DPA + KSA appendix
NVIDIA Cloud FunctionsEU — FrankfurtGPU inference for non-restricted workloadsSCCs 2021/914 M2
Snowflake Inc.UAE — me-central-1Analytics warehouse (anonymised telemetry only)DPA + customer-managed keys
HubSpot Inc.EU — FrankfurtMarketing CRM (non-customer contact data)SCCs 2021/914 M2
Atlassian Pty LtdEU — FrankfurtTicketing and source controlSCCs 2021/914 M2
Cloudflare Inc.Global edgeCDN, WAF, DDoS mitigationSCCs + cache scope limit
Auth0 by OktaEU — FrankfurtAuthentication for managed-service customersSCCs + EU isolation
SentryEU — FrankfurtError telemetry (scrubbed)SCCs + PII scrubbing
DatadogEU — FrankfurtInfra observability (no customer data)SCCs + scope limit

For per-engagement variations (e.g. a customer-specific deployment that uses none of the marketing or analytics processors), the engagement-level DPA Annex II lists the operative sub-processors only. See the privacy policy for the DPO contact and the data-subject rights process.

A secure operations centre with status panels showing live monitoring of customer-facing systems

Incident response posture

One-hour acknowledgement. Twenty-four-hour customer notification.

The runbook, the escalation tree, and the named on-call contact for the first 90 days of every engagement are inside the Vendor Security Pack. Below is the headline timeline a TPRM analyst can pin to the wall.

T+0

Detection

SIEM correlation, EDR alert, or customer report. Auto-page to on-call.

T+1 hour

Acknowledgement

Named engineer accepts page. Incident ticket opened. Severity classified.

T+24 hours

Customer notification

On confirmed personal data incident — customer notified, ahead of PDPL Art. 9 / GDPR Art. 33 regulator window.

T+72 hours

Regulator + post-mortem

PDPL / supervisory authority notified where required. 14-day post-mortem with named owner per action.

How we compare

Big-4 InfoSec packs, hyperscaler MSPs, offshore AI vendors, and boutiques — the honest read.

The four alternatives a UAE CISO weighs when a TPRM workflow lands. Where Brocode is not the right fit (e.g. visitor needs only a hyperscaler attestation), we will tell you on the first call.

CapabilityBrocodeBig-4 consultanciesHyperscaler MSP / resellerOffshore AI vendorBoutique AI consultancy
Time from NDA to Vendor Security PackSame day3–6 weeks (legal routing)Hyperscaler page only"On request" — undefinedNo pack — marketing slides
SOC 2 Type II in own nameYes — Big-4 affiliated CPAYes — but partner-pool scopedUnderlying hyperscaler only
ISO 42001 AI management systemCertified Jan 2026In preparation
UAE PDPL + TDRA + NESA evidenceArticle-mappedRegional adaptationGeneric data residency only
Customer-managed keys on UAE sovereignBYOK / HYOK defaultPremium tier onlyHyperscaler-definedNo formal posture
Sub-processor register with country of processing11 listed, monthly reviewAggregated regional poolHyperscaler list — not vendorNot published
Named security contact (photo + booking link)Head of InfoSec, directRegional partner poolGeneric shared mailboxGeneric shared mailboxNo public contact
Open critical / high findings0 / 0 (last pen test Mar 2026)Not disclosedNot applicableNot disclosedNot disclosed

Free download

Brocode Vendor Security Pack (NDA-gated)

A single zipped bundle (≈45 MB) containing SOC 2 Type II full report, ISO 27001 certificate + SOA, penetration test executive summary, DPA template, sub-processor register, BCP / DR summary, incident response policy, ISO 42001 policy, and a pre-filled CAIQ v4.

  • SOC 2 Type II — Big-4 affiliated CPA firm, signed 14 March 2026
  • ISO/IEC 27001:2022 certificate, SOA (93 controls) and BSI surveillance letter
  • CREST-accredited penetration test — full report (executive summary pre-NDA)
  • DPA template — UAE PDPL + GDPR + DIFC DP Law aligned, SCCs pre-filled
  • Sub-processor register — 11 entries, country of processing, safeguards
  • CAIQ v4 — pre-filled Cloud Security Alliance Consensus Assessment
  • ISO 42001:2023 AI management system policy and scope
  • BCP / DR summary — RTO 4h, RPO 15m, last DR test Q4 2025
  • NDA gating: submit your standard NDA or use ours; we countersign within 24 working hours.

Instant download. No spam. Unsubscribe any time.

From real TPRM workflows

Frequently asked by CISOs.

Twelve questions distilled from the OneTrust, CyberGRX, and ServiceNow VRM workflows we have answered in the last 24 months. Where an answer needs an artefact, the artefact lives in the Vendor Security Pack.

Book the 60-minute review
  • Yes. Our SOC 2 Type II audit was signed on 14 March 2026 by a Big-4 affiliated CPA firm and covers the trust services criteria Security, Availability, Confidentiality, and Processing Integrity for the 12 months ending 31 December 2025. The full report is available under NDA in the Vendor Security Pack. A bridge letter from the auditor covering the period between the audit close and today is also included.

60-minute security review

Sit our Head of InfoSec next to your TPRM analyst.

We walk the Vendor Security Pack, take questions on the residual-risk register, and agree the artefacts your committee will see. We reply within one business day.

Direct WhatsApp: +971 50 761 2213

Security email: security@brocode.ae

HQ: Al Maryah Island, ADGM, Abu Dhabi

Quote request

Book a 60-minute security review with our Head of Information Security

A senior security engineer from the Brocode practice walks your TPRM analyst through the Vendor Security Pack and the residual-risk position. We reply within one business day.

Prefer chat? Message us on WhatsApp — we'll see it within working hours.

Download packWhatsApp