Customer documentation¶
Welcome. This directory holds everything a prospective customer (particularly a CEE bank's procurement, security, or compliance team) needs to evaluate Secruna as a vendor and to onboard once a contract is signed.
The pages below are drafts — the legal templates have been
authored by Secruna's engineering team to reflect what we
actually do and intend to commit to operationally, but they
must be reviewed by qualified counsel before being signed or
made public. Each legal document carries a TODO: review by
counsel banner; do not strip those banners until counsel has
signed off.
Frameworks we cover¶
Plain-English guides to the rulebooks Secruna assembles evidence for. Each guide opens with a one-paragraph "what is X and why does it matter to you" lead, then lists exactly what we ship today and where v1 still has gaps.
- NCSC Cyber Assessment Framework — UK public sector + CNI gateway, consumed by GovAssure
- NIS2 Directive — EU essential + important entities, Member-State competent authority
- DORA (Digital Operational Resilience Act) — EU financial firms, directly applicable since 17 January 2025
The remaining four frameworks (EU AI Act, RICS Responsible Use of
AI, UK Defence AI Playbook, Defence Standard 05-138, Secure by
Design) currently live as marketing-site deep pages under
https://secruna.com/use-cases/; a customer-doc walkthrough for
each is on the backlog.
Connector setup¶
If you are evaluating which connectors to install, start with the overview. If you already know which ones you want, jump straight to the per-connector page.
- Overview & decision tree
- Azure — Cognitive Services, Azure ML, Bot Service, AI Search; passive twin reads Activity Log
- AWS — Bedrock, SageMaker; passive twin reads CloudTrail
- GCP — Vertex AI; passive twin reads Cloud Logging
- GitHub — Copilot seats, AI dependencies, workflow YAML, code-search
- Microsoft 365 (Power Platform) — Power Platform admin scope
- OpenAI — admin API key
- Anthropic — admin API key
- Databricks — OAuth M2M Service Principal
Legal and compliance¶
For procurement, security questionnaires, DPA review:
- DPA template — the Article 28 GDPR processor agreement we propose to sign
- Privacy policy — public-facing privacy statement
- Terms of Service — proposed master subscription terms
- Subprocessor list — third parties we contract with on your behalf
- Data retention policy — how long we keep what
Operational references¶
For your security questionnaire, here is what we are willing to share publicly today (these are repository documents we maintain for ourselves, not customer-polished prose — they are honest about gaps):
../ops/incident-response.md— incident response runbook, including DR posture and RTO/RPO targets../ops/slos.md— defined Service Level Objectives../ops/uptime-monitoring.md— uptime monitoring + status-page setup../roadmap/2026-05-03-mvp-priorities.md— current public product priorities
Support and contacts¶
| Purpose | Contact |
|---|---|
| Status page | https://status.secruna.com |
| Customer support | TODO support@secruna.com (alias to be configured) |
| Privacy / data subject rights | TODO legal@secruna.com (alias to be configured) |
| Security disclosure | TODO security@secruna.com (alias to be configured) |
For incidents affecting the public service, the status page is the canonical communication channel; we update it within 5 minutes of detection for S0/S1 incidents per our incident response runbook.
What this directory does not yet contain¶
Items below are tracked for inclusion before first paying customer:
- A polished public security white paper (the DPA + the ops/incident-response runbook overlap with what one would say there — we will distil a 5-page version when there is buyer pressure).
- Screenshots illustrating the connector flows. Today every
connector page carries
(screenshot placeholder TODO)markers; capturing them requires a stable demo tenant which is spun up but not yet seeded with all connector types. - A signed independent attestation (SOC 2, ISO 27001). We are honest in the DPA that these are not yet held; pursuing them is on the roadmap.
- Translations. English-only for v1; Polish, Czech, and German translations are roadmap items.
Document hygiene¶
Every document in this directory:
- Carries a
Last updateddate in its header. - Cross-links to siblings where relevant.
- Uses plain English; minimum jargon, no marketing fluff.
- Marks TODOs explicitly rather than papering over gaps.
If you find an inaccuracy, a typo, or a clause that is unclear,
email TODO support@secruna.com — we maintain these documents
in the same repository as the source code and a fix can ship in
hours, not weeks.