Security Evidence Pack · Northwind Financial
Disclosures & evidence sources
Point-in-time
2026-07-02
Section 5
Disclosures
The plain-language disclosures every pack ships with. Quoted here as they appear in the finalized document.
Nature of this document
"This Security Evidence Pack is a point-in-time snapshot of evidence collected from connected sources on the date shown. It is not a compliance certification, an audit, or an audit opinion. Control references are informational mappings that indicate supporting evidence exists; they do not assert that a control was formally tested."
Insurer audience
"Prepared to support a cyber-insurance underwriting conversation. It does not constitute an insurance application or a guarantee of coverage."
Connector scope
The Microsoft 365 connector is read-only. It collects the user roster, MFA registration posture, and a Microsoft Secure Score snapshot. It does not collect mailbox or email content, conditional-access policies, or security defaults, and it never writes back to the tenant.
MFA measurement
"MFA Source: Per User Methods" indicates the aggregate Entra registration report was unavailable, so each user was checked individually for strong second factors. Passwords and email are not counted as MFA.
Integrity & sharing
Finalized packs are rendered once, frozen, and fingerprinted with a SHA-256 integrity hash. Shared links expire (30-day default), are revocable, are excluded from search indexing, and every view is audit-logged.
Evidence sources consulted
CollectedMicrosoft 365 — user rosterread-only · 2026-07-02
CollectedMicrosoft 365 — MFA registration postureread-only · 2026-07-02
CollectedMicrosoft 365 — Secure Score snapshotread-only · 2026-07-02
Not connectedDevice / MDM — endpoint postureno evidence collected
Sources are recorded whether or not they returned evidence — including unavailable ones — so the reader can see exactly what was and was not consulted.