Our position
Evidence before assurances
CSDocs is offered as private documentation for a customer’s NetSuite environment. It is not a public publishing service. Security depends on the complete path—from NetSuite access and processing through hosting, authentication, support, backups, and deletion—so broad claims are not a substitute for reviewing that path.
CSDocs does not currently claim SOC 2 certification or any other independent security certification. Nothing on this page should be read as a certification, an audit opinion, or a guarantee that an incident can never occur.
Service commitments
What CSDocs commits to today
Scope access before onboarding
Before customer data is connected, CSDocs will explain the requested access path, the information expected to be processed, and the people expected to have operational access.
Keep documentation private
Customer documentation is provided as a private workspace. A customer must authorize the people who receive access; it is not intentionally published for public discovery.
Separate payment handling
Trial and subscription payment details are collected through Stripe’s hosted checkout and billing services. The CSDocs marketing-funnel database does not store card information.
Define offboarding before onboarding
Before customer data is connected, CSDocs documents how access, exports, active production copies, and backups will be handled when service ends. A fixed deletion timeline is not promised until it has been verified.
Data lifecycle
Where information enters the service
The table below states what is known and flags the details that must be confirmed during the infrastructure audit.
| Stage | Known treatment | Verification status |
|---|---|---|
| Explore CSDocs | The CSDocs funnel measurement uses a random, page-load-specific token and does not use browser cookies, local storage, or session storage. When a trial link is opened, that opaque token is sent to Stripe as the checkout reference. | Defined |
| Start a trial | Stripe collects contact and payment details. CSDocs receives the subscription information needed to operate and support the account. | Confirmed provider |
| Onboard | CSDocs must describe the exact NetSuite access route, permissions, imported data categories, and operator access before a customer connection is authorized. | Audit required |
| Use the service | Customer documentation is delivered through a private workspace. Authentication controls, infrastructure, regions, encryption implementation, and administrative logging remain in the verification register. | Audit required |
| End a subscription | Offboarding actions, export availability, deletion timing, and backup treatment are confirmed before onboarding or in a signed order. | Audit required |
Verification register
Claims awaiting technical evidence
These items are deliberately not described as completed controls. They must be checked against the live production architecture, documented, and approved before the corresponding claims appear on the CSDocs sales page.
- NetSuite connection and permissions The authentication method, role permissions, connection lifetime, revocation path, and whether every data path is technically read-only.
- AI processing Every model or AI service used, the data sent to it, retention behavior, training settings, regions, and fallback paths.
- Hosting and storage Production providers, storage locations, tenant separation, encryption in transit and at rest, key management, and patching responsibilities.
- Identity and operator access Customer authentication, authorization boundaries, privileged access, joiner and leaver handling, and audit-log coverage.
- Logs, backups, and deletion Log categories and retention, backup frequency and lifetime, cache and export copies, restoration access, and verifiable deletion behavior.
- Response and suppliers Incident-response ownership, notification workflow, vulnerability handling, availability monitoring, and the complete subprocessor register.
They make a security review useful. A customer can see exactly which questions have firm answers and which require completion before onboarding.
Shared responsibility
What customers control
Customers remain responsible for selecting appropriate NetSuite roles, authorizing CSDocs users, removing access when a person changes roles, protecting their own credentials, and deciding whether the service fits their legal and compliance requirements.
Before onboarding, ask for the current connection diagram and permission list. Do not provide broader access than the documented workflow requires.
Contact
Report a security concern
Send suspected vulnerabilities, unauthorized access, or security questions directly to Benjamin Rogol. Include enough detail to reproduce the issue, but do not email credentials, payment-card information, or customer documents.
ben@thecloudsteward.com