Our security questionnaire, filled in up front
Here are 44 answers to what IT asks a supplier about Contember Fabrika: where the apps run, where the data lives, how people sign in, how a change gets into production, and what happens if we part ways. Each answer says whether it's in place today or something we still agree with you.
Download the spreadsheet and paste the answers into your supplier file or your own questionnaire. To point at one answer, use its ID in the link, for example #c2 for multi-factor authentication. The exact wording of the commitments is in the contract.
Updated 28 September 2026
Czech version (XLSX)
What does IT ask when vetting a supplier?
The questions come from typical supplier questionnaires and from what IT asks us on calls. They're grouped by area; open the one you need.
What the status means
- In place today
- Agreed with you
- Set in the contract
- In progress
- Not available
A Architecture and hosting 9 questions
Where do the apps run?
In your own installation of the Fabrika platform, which each company has to itself. It runs with one provider, in a cloud account we set up in your company's name: Cloudflare or Zerops, or AWS if you prefer.
Do you share the installation with other customers?
No. Each company has its own installation and shares it with no one.
Can Fabrika run on AWS?
Yes, by arrangement. Our primary choices are Cloudflare and Zerops. If you want AWS, we set it up individually when we set up Fabrika, in an AWS account registered to your company. We pick the region to match your requirements.
Can we run Fabrika on our own servers, on Azure or with another provider?
No. Today Fabrika runs on Cloudflare, on Zerops and, by arrangement, on AWS. We don't run it on your own servers, on Azure or in any other cloud.
Can the apps be reached from the internet?
The apps have no public address of their own. Every request goes through one entry point in the platform, which lets in only verified users. When the access rules are missing or unclear, the entry stays shut.
Are testing and production separated?
Yes. Testing and production are separate environments, each with its own network. Whatever you try in testing can't touch production data.
Where are the apps' keys and passwords stored?
The cloud provider holds the values, not our database. Each app sees only its own. Through the platform they can be written, but never read back.
Who patches the platform?
We do. We keep the platform patched, continuously and without you having to ask.
How are errors and outages monitored?
Errors from all apps are collected in one place, grouped, and can be assigned and resolved. The platform checks that apps respond, and on a new error or a sudden spike it sends an alert.
B Data and where it lives 5 questions
Where does the data physically live?
In your cloud account, with the provider we choose during setup: Cloudflare, Zerops or, if you prefer, AWS. Zerops is a Czech company (Zerops s.r.o., Prague) with a data centre in Prague. Cloudflare and AWS are US companies. On AWS, we pick the region to match your requirements.
Will the data stay in the EU?
With Zerops, it sits in a data centre in Prague. With Cloudflare, we don't promise EU location in this questionnaire: it depends on the specific service and how the account is set up. We go through Cloudflare's region and terms against your requirements before setup. On AWS, we pick the region to match them. If keeping the data in the Czech Republic is a must, we'll talk about Zerops.
What if a foreign authority requests the data? What about the US CLOUD Act?
Cloudflare and AWS are US companies, Zerops is a Czech one. What that means for authorities' access to your data, we're glad to go through with your lawyer.
What is our relationship with the cloud provider, and what is your role?
The cloud account is registered to your company, so you deal with the cloud provider directly, including its data processing terms. Our access to your data and its scope are set out in the contract between you and us.
Our app runs on Supabase. What happens to the data in a takeover?
We decide it together, deliberately. Either the data moves to a database in your cloud account, or you run Supabase in your own cloud account, or it stays where it is. Each option has a different effect on where the data lives.
C Sign-in and access 8 questions
How do users sign in?
With their company account through your identity provider, for example Google, Microsoft Entra or Okta, with one sign-in for all apps. Anyone without a company account, an outside contractor for example, uses a password. No admin can set or read it.
What about multi-factor authentication (MFA) with a company account?
Sign-in goes through your identity provider, so MFA works the way your company has it set up there.
And with password sign-in?
Multi-factor authentication for password sign-in is in progress. Until then, we recommend giving a company account to everyone who can have one.
How are permissions set?
By role, separately for each app. An app declares which roles it knows; which person gets which one is up to you. A new version of the app won't overwrite the permissions you set.
How is access removed when someone leaves or changes roles?
Once you block the company account at your identity provider, the person can no longer sign in to the apps. Roles in individual apps are changed or removed in the platform.
Who on your side has access to production?
We do, to the extent needed for change review, deployment and patches. Sign-ins and access changes in the platform are recorded. Access to the cloud account itself stays with you. Exactly who on our side has access, we agree during setup.
Are sign-ins and access changes recorded?
Yes. Sign-ins and changes to access and roles go into an audit log you can see in the console. Every deployment has its own record with a log: which version, when, and how it went.
How long are the records kept?
Records of changes to access and roles are kept. We set the retention period to your requirements; as a setting in the platform, this is in progress.
D Changes and development 5 questions
How does a change get into production?
In four steps. Your person builds with AI, working from the brief and the code. The change goes to Git with an author, a time and a description. We review it before deployment. Then it goes live, leaves a record, and you get a report: what changed, what we checked and how it came out.
Are changes reviewed by a person or a tool?
A person. Change review is our service: someone on our side goes through every change before it's deployed. We look at permissions, handling of data, and anything that could open a door that should stay shut. Nothing reaches production any other way.
Where is the source code, and who owns it?
In Git. Every change there has an author, a time and a description, and nothing gets copied onto the server by hand. The apps' code is yours.
Who can build apps?
Your person with AI, your developer or agency, or us together with your person during a kickstart. Everyone takes the same path: through Git and our review.
Will you take over an app built elsewhere, say in Lovable, Cursor or by a freelancer?
Yes, as long as it's code that can run outside the tool it was made in. We make small changes and deploy it into your cloud account. Apps clicked together in Bubble and similar builders we can't take over.
E Operations, incidents and backups 5 questions
How do you handle backups and recovery?
We set up backups and recovery with you, to the extent you need: what gets backed up, how often, how long it's kept and how quickly the data has to be back. It's our service, not something the platform does on its own, so we agree on the scope when we set up Fabrika.
What happens during an incident?
The platform collects errors and alerts on new ones or on a sudden spike. We help find out what happened in the app, fix it, and put together the documents for the report you have to file.
How soon do you tell us about an incident on your side?
The deadline is set in the contract.
What SLA do you offer?
We run operations and change review under an SLA. The specific level and the exact wording of the commitments are set in the contract.
Who fixes bugs in the apps when the code was written by our developer or agency?
We do, within the SLA.
F AI 4 questions
Which AI do you use, and on whose account?
The one you choose. AI always runs on your own plan with the provider you pick, under your terms. We're happy to advise on picking the provider.
Does the AI work with production data?
No. Your person builds with AI on their own computer, working from the brief and the code. The production database sits in a private network and the apps have no public address, so building never touches live data. The AI only gets data if someone deliberately gives it some.
Is anything trained on our data?
We don't train anything on your data. What the AI provider may do with data is set by the terms of your plan.
Can the AI deploy a change on its own?
No. What the AI writes goes the same way as any other change: through Git and our review.
G Suppliers and contract 6 questions
Who are your subcontractors?
For Fabrika you have one supplier: us. The cloud account with Cloudflare, Zerops or AWS is registered to your company, so you have that relationship directly. The AI runs on your own plan. We don't resell you either of them.
Who is our contract with when our agency builds the apps?
With us, directly. You hire the developer or agency yourself; the Fabrika contract is always between you and us.
Do you have ISO 27001 or SOC 2 certification?
No. Instead of a certificate, we go through it with your IT on a technical call: what the platform handles, how change review works and who has access to what. The cloud provider's certifications you can check with them directly, since the account is yours.
Do you run penetration tests?
We don't have a penetration test of the platform yet. What we rely on is a person reviewing every change before deployment, and a single entry point to the apps that lets in only verified users.
Can you provide a software bill of materials (SBOM)?
We don't provide an SBOM yet. The apps' code is in your own Git.
Will you accept our security requirements for suppliers, for example under Annex 2 of Czech Decree 410/2025?
Send them to us in advance. We go through them with you before the contract is signed and tell you plainly what we can meet and what we can't.
H Exit 2 questions
What if we part ways?
The apps' code is yours, the data and the domains are in your account. The system keeps running without us, and the next person picks it up from Git. What stops is our change review and support.
Do we have to pull our data out of your systems when we leave?
No. The data sits in your cloud account from day one, so nothing has to move when you leave.
Need it as a spreadsheet?
The same 44 questions and answers as on this page, one row each: ID, area, question, answer, status and a link back to the answer here. Filter by status to see at a glance what's in place today and what we still need to agree.
Updated 28 September 2026
Security questionnaire, English
XLSX · 44 questions
Bezpečnostní dotazník, Czech
XLSX · 44 questions
What's missing here, and what do we do about it?
Some questions in a supplier questionnaire we can't answer with a plain yes today. Here they are in one place, with what we offer instead.
ISO 27001 or SOC 2 certification
Instead, we go through the platform, the change review and who has access to what with your IT on a technical call. The cloud provider's certifications you check with them directly.
#g3Penetration test and SBOM
What we rely on is a person reviewing every change before deployment and a single entry point that lets in only verified users.
#g4MFA with password sign-in
With a company account, MFA works the way you have it set up at your identity provider. Until password MFA is ready, give a company account to everyone who can have one.
#c3How long records are kept
Records of access and role changes are kept. Tell us the retention you need during setup.
#c8Data with US providers and US law
Cloudflare and AWS are US companies. We don't promise EU location with Cloudflare here, we go through the region and terms against your requirements. On AWS, we pick the region to match them. The legal side we go through with your lawyer. If you need the data in the Czech Republic, we'll talk about Zerops.
#b2Incident deadlines and SLA figures
How soon we tell you about an incident on our side, and the service level, are set in the contract, not on the website.
#e3When is Fabrika not for you?
-
Your rules require a certified supplier (ISO 27001, SOC 2) as a condition. We don't meet that today.
-
You need a penetration test report on the platform before signing. We don't have one yet.
-
The apps have to run on your own servers, on Azure or with another provider. Fabrika runs on Cloudflare or Zerops and, by arrangement, on AWS. Nowhere else for now.
What people ask about the questionnaire
Can we copy the answers into our own questionnaire or supplier file?
Yes, that's what the spreadsheet is for. Keep in mind the answers describe how Fabrika works; the exact wording of the commitments is in the contract.
We have our own questionnaire (SIG, CAIQ or our own template). Will you fill it in?
Yes. Send it to sales@contember.com, or bring it to a call with our engineer.
Do the answers apply to our installation?
They describe how Fabrika works for every company. Where something is decided with you (the cloud provider, backups, who on our side has access, how long records are kept), the answer says so and we set it during setup.
Is this enough for NIS2?
It helps with the part about the supplier: change management, exit, who has access. Whether and how the Czech Cyber Security Act applies to you is best assessed with your lawyer or auditor. This isn't legal advice. What the platform handles is described in more detail on the Security page.
Send us your questionnaire, we'll fill it in.
Got your own template or a checklist from your auditor? Send it over, or go through it with our engineer in half an hour: where it runs, how sign-in and permissions work, how a change gets into production.