Our security questionnaire, filled in up front

Here are 44 answers to what IT asks a supplier about Contember Fabrika: where the apps run, where the data lives, how people sign in, how a change gets into production, and what happens if we part ways. Each answer says whether it's in place today or something we still agree with you.

Download the spreadsheet and paste the answers into your supplier file or your own questionnaire. To point at one answer, use its ID in the link, for example #c2 for multi-factor authentication. The exact wording of the commitments is in the contract.

Updated 28 September 2026

Czech version (XLSX)

What does IT ask when vetting a supplier?

The questions come from typical supplier questionnaires and from what IT asks us on calls. They're grouped by area; open the one you need.

What the status means

  • In place today
  • Agreed with you
  • Set in the contract
  • In progress
  • Not available
A Architecture and hosting 9 questions
A1

Where do the apps run?

In your own installation of the Fabrika platform, which each company has to itself. It runs with one provider, in a cloud account we set up in your company's name: Cloudflare or Zerops, or AWS if you prefer.

In place today
A2

Do you share the installation with other customers?

No. Each company has its own installation and shares it with no one.

In place today
A3

Can Fabrika run on AWS?

Yes, by arrangement. Our primary choices are Cloudflare and Zerops. If you want AWS, we set it up individually when we set up Fabrika, in an AWS account registered to your company. We pick the region to match your requirements.

Agreed with you
A4

Can we run Fabrika on our own servers, on Azure or with another provider?

No. Today Fabrika runs on Cloudflare, on Zerops and, by arrangement, on AWS. We don't run it on your own servers, on Azure or in any other cloud.

Not available
A5

Can the apps be reached from the internet?

The apps have no public address of their own. Every request goes through one entry point in the platform, which lets in only verified users. When the access rules are missing or unclear, the entry stays shut.

In place today
A6

Are testing and production separated?

Yes. Testing and production are separate environments, each with its own network. Whatever you try in testing can't touch production data.

In place today
A7

Where are the apps' keys and passwords stored?

The cloud provider holds the values, not our database. Each app sees only its own. Through the platform they can be written, but never read back.

In place today
A8

Who patches the platform?

We do. We keep the platform patched, continuously and without you having to ask.

In place today
A9

How are errors and outages monitored?

Errors from all apps are collected in one place, grouped, and can be assigned and resolved. The platform checks that apps respond, and on a new error or a sudden spike it sends an alert.

In place today
B Data and where it lives 5 questions
B1

Where does the data physically live?

In your cloud account, with the provider we choose during setup: Cloudflare, Zerops or, if you prefer, AWS. Zerops is a Czech company (Zerops s.r.o., Prague) with a data centre in Prague. Cloudflare and AWS are US companies. On AWS, we pick the region to match your requirements.

In place today
B2

Will the data stay in the EU?

With Zerops, it sits in a data centre in Prague. With Cloudflare, we don't promise EU location in this questionnaire: it depends on the specific service and how the account is set up. We go through Cloudflare's region and terms against your requirements before setup. On AWS, we pick the region to match them. If keeping the data in the Czech Republic is a must, we'll talk about Zerops.

Agreed with you
B3

What if a foreign authority requests the data? What about the US CLOUD Act?

Cloudflare and AWS are US companies, Zerops is a Czech one. What that means for authorities' access to your data, we're glad to go through with your lawyer.

Agreed with you
B4

What is our relationship with the cloud provider, and what is your role?

The cloud account is registered to your company, so you deal with the cloud provider directly, including its data processing terms. Our access to your data and its scope are set out in the contract between you and us.

Set in the contract
B5

Our app runs on Supabase. What happens to the data in a takeover?

We decide it together, deliberately. Either the data moves to a database in your cloud account, or you run Supabase in your own cloud account, or it stays where it is. Each option has a different effect on where the data lives.

Agreed with you
C Sign-in and access 8 questions
C1

How do users sign in?

With their company account through your identity provider, for example Google, Microsoft Entra or Okta, with one sign-in for all apps. Anyone without a company account, an outside contractor for example, uses a password. No admin can set or read it.

In place today
C2

What about multi-factor authentication (MFA) with a company account?

Sign-in goes through your identity provider, so MFA works the way your company has it set up there.

In place today
C3

And with password sign-in?

Multi-factor authentication for password sign-in is in progress. Until then, we recommend giving a company account to everyone who can have one.

In progress
C4

How are permissions set?

By role, separately for each app. An app declares which roles it knows; which person gets which one is up to you. A new version of the app won't overwrite the permissions you set.

In place today
C5

How is access removed when someone leaves or changes roles?

Once you block the company account at your identity provider, the person can no longer sign in to the apps. Roles in individual apps are changed or removed in the platform.

In place today
C6

Who on your side has access to production?

We do, to the extent needed for change review, deployment and patches. Sign-ins and access changes in the platform are recorded. Access to the cloud account itself stays with you. Exactly who on our side has access, we agree during setup.

Agreed with you
C7

Are sign-ins and access changes recorded?

Yes. Sign-ins and changes to access and roles go into an audit log you can see in the console. Every deployment has its own record with a log: which version, when, and how it went.

In place today
C8

How long are the records kept?

Records of changes to access and roles are kept. We set the retention period to your requirements; as a setting in the platform, this is in progress.

In progress
D Changes and development 5 questions
D1

How does a change get into production?

In four steps. Your person builds with AI, working from the brief and the code. The change goes to Git with an author, a time and a description. We review it before deployment. Then it goes live, leaves a record, and you get a report: what changed, what we checked and how it came out.

In place today
D2

Are changes reviewed by a person or a tool?

A person. Change review is our service: someone on our side goes through every change before it's deployed. We look at permissions, handling of data, and anything that could open a door that should stay shut. Nothing reaches production any other way.

In place today
D3

Where is the source code, and who owns it?

In Git. Every change there has an author, a time and a description, and nothing gets copied onto the server by hand. The apps' code is yours.

In place today
D4

Who can build apps?

Your person with AI, your developer or agency, or us together with your person during a kickstart. Everyone takes the same path: through Git and our review.

In place today
D5

Will you take over an app built elsewhere, say in Lovable, Cursor or by a freelancer?

Yes, as long as it's code that can run outside the tool it was made in. We make small changes and deploy it into your cloud account. Apps clicked together in Bubble and similar builders we can't take over.

In place today
E Operations, incidents and backups 5 questions
E1

How do you handle backups and recovery?

We set up backups and recovery with you, to the extent you need: what gets backed up, how often, how long it's kept and how quickly the data has to be back. It's our service, not something the platform does on its own, so we agree on the scope when we set up Fabrika.

Agreed with you
E2

What happens during an incident?

The platform collects errors and alerts on new ones or on a sudden spike. We help find out what happened in the app, fix it, and put together the documents for the report you have to file.

In place today
E3

How soon do you tell us about an incident on your side?

The deadline is set in the contract.

Set in the contract
E4

What SLA do you offer?

We run operations and change review under an SLA. The specific level and the exact wording of the commitments are set in the contract.

Set in the contract
E5

Who fixes bugs in the apps when the code was written by our developer or agency?

We do, within the SLA.

In place today
F AI 4 questions
F1

Which AI do you use, and on whose account?

The one you choose. AI always runs on your own plan with the provider you pick, under your terms. We're happy to advise on picking the provider.

In place today
F2

Does the AI work with production data?

No. Your person builds with AI on their own computer, working from the brief and the code. The production database sits in a private network and the apps have no public address, so building never touches live data. The AI only gets data if someone deliberately gives it some.

In place today
F3

Is anything trained on our data?

We don't train anything on your data. What the AI provider may do with data is set by the terms of your plan.

In place today
F4

Can the AI deploy a change on its own?

No. What the AI writes goes the same way as any other change: through Git and our review.

In place today
G Suppliers and contract 6 questions
G1

Who are your subcontractors?

For Fabrika you have one supplier: us. The cloud account with Cloudflare, Zerops or AWS is registered to your company, so you have that relationship directly. The AI runs on your own plan. We don't resell you either of them.

In place today
G2

Who is our contract with when our agency builds the apps?

With us, directly. You hire the developer or agency yourself; the Fabrika contract is always between you and us.

In place today
G3

Do you have ISO 27001 or SOC 2 certification?

No. Instead of a certificate, we go through it with your IT on a technical call: what the platform handles, how change review works and who has access to what. The cloud provider's certifications you can check with them directly, since the account is yours.

Not available
G4

Do you run penetration tests?

We don't have a penetration test of the platform yet. What we rely on is a person reviewing every change before deployment, and a single entry point to the apps that lets in only verified users.

Not available
G5

Can you provide a software bill of materials (SBOM)?

We don't provide an SBOM yet. The apps' code is in your own Git.

Not available
G6

Will you accept our security requirements for suppliers, for example under Annex 2 of Czech Decree 410/2025?

Send them to us in advance. We go through them with you before the contract is signed and tell you plainly what we can meet and what we can't.

Agreed with you
H Exit 2 questions
H1

What if we part ways?

The apps' code is yours, the data and the domains are in your account. The system keeps running without us, and the next person picks it up from Git. What stops is our change review and support.

In place today
H2

Do we have to pull our data out of your systems when we leave?

No. The data sits in your cloud account from day one, so nothing has to move when you leave.

In place today

Need it as a spreadsheet?

The same 44 questions and answers as on this page, one row each: ID, area, question, answer, status and a link back to the answer here. Filter by status to see at a glance what's in place today and what we still need to agree.

Updated 28 September 2026

Security questionnaire, English

XLSX · 44 questions

Download ↓

Bezpečnostní dotazník, Czech

XLSX · 44 questions

Download ↓

What's missing here, and what do we do about it?

Some questions in a supplier questionnaire we can't answer with a plain yes today. Here they are in one place, with what we offer instead.

We don't have it

ISO 27001 or SOC 2 certification

Instead, we go through the platform, the change review and who has access to what with your IT on a technical call. The cloud provider's certifications you check with them directly.

#g3
We don't have them yet

Penetration test and SBOM

What we rely on is a person reviewing every change before deployment and a single entry point that lets in only verified users.

#g4
In progress

MFA with password sign-in

With a company account, MFA works the way you have it set up at your identity provider. Until password MFA is ready, give a company account to everyone who can have one.

#c3
In progress as a setting

How long records are kept

Records of access and role changes are kept. Tell us the retention you need during setup.

#c8
We go through it with you

Data with US providers and US law

Cloudflare and AWS are US companies. We don't promise EU location with Cloudflare here, we go through the region and terms against your requirements. On AWS, we pick the region to match them. The legal side we go through with your lawyer. If you need the data in the Czech Republic, we'll talk about Zerops.

#b2
In the contract

Incident deadlines and SLA figures

How soon we tell you about an incident on our side, and the service level, are set in the contract, not on the website.

#e3

When is Fabrika not for you?

  • Your rules require a certified supplier (ISO 27001, SOC 2) as a condition. We don't meet that today.

  • You need a penetration test report on the platform before signing. We don't have one yet.

  • The apps have to run on your own servers, on Azure or with another provider. Fabrika runs on Cloudflare or Zerops and, by arrangement, on AWS. Nowhere else for now.

What people ask about the questionnaire

Can we copy the answers into our own questionnaire or supplier file?

Yes, that's what the spreadsheet is for. Keep in mind the answers describe how Fabrika works; the exact wording of the commitments is in the contract.

We have our own questionnaire (SIG, CAIQ or our own template). Will you fill it in?

Yes. Send it to sales@contember.com, or bring it to a call with our engineer.

Do the answers apply to our installation?

They describe how Fabrika works for every company. Where something is decided with you (the cloud provider, backups, who on our side has access, how long records are kept), the answer says so and we set it during setup.

Is this enough for NIS2?

It helps with the part about the supplier: change management, exit, who has access. Whether and how the Czech Cyber Security Act applies to you is best assessed with your lawyer or auditor. This isn't legal advice. What the platform handles is described in more detail on the Security page.

Send us your questionnaire, we'll fill it in.

Got your own template or a checklist from your auditor? Send it over, or go through it with our engineer in half an hour: where it runs, how sign-in and permissions work, how a change gets into production.