> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/company-operating-manual/security-compliance-and-data/supplier-security-requirements.md).

# Supplier Security Requirements

### Purpose

Suppliers must meet security requirements appropriate to the work they perform.

### Supplier Security Controls

Suppliers may be required to provide:

* security policy evidence
* personnel checks
* confidentiality commitments
* access control compliance
* secure development practices
* incident notification process
* insurance evidence
* data handling compliance
* audit cooperation

### Supplier Access

Supplier access should be:

* approved
* limited
* monitored
* time-bound
* removed promptly when no longer required
