RFP / RFI response guide
Most procurement questionnaires ask the same questions. This page names what Nebbos has already answered publicly (so your procurement team doesn’t need to ask us), what’s available under NDA, and what to request when the public docs don’t cover it.
What’s already answered publicly
Point your procurement team at these pages directly. Every question below is a section on that page, so a copy-paste into an RFP response is a fifteen-minute exercise.
Security & compliance
| Question class | Where it’s answered |
|---|---|
| Encryption at rest / in transit | Product datasheet → Security controls |
| Key management (KMS, HSM, secure element) | Product datasheet, Cradle provisioning |
| Access control model (RBAC, ABAC, tier) | Authentication & tiers |
| Row-level isolation / multi-tenant separation | Row-level isolation |
| SOC 2 / ISO 27001 / HIPAA / GDPR / EU AI Act | Compliance posture |
| Audit logging and log tamper-resistance | The audit chain |
| Vulnerability disclosure and bug bounty | Vulnerability disclosure |
| Accessibility (WCAG, Section 508, VPAT) | Accessibility (VPAT) |
| Business continuity / disaster recovery | Business continuity & DR |
| Subprocessors and data flow | Subprocessor list |
Operations & support
| Question class | Where it’s answered |
|---|---|
| Uptime SLA and service credits | SLA |
| Response times by severity | SLA, Incident response |
| Incident communication commitment | Incident response |
| Public system status board | System status → status.nebbos.ai |
| Change management (deprecation, versioning) | Versioning & changelog, Deprecation policy |
Product & integration
| Question class | Where it’s answered |
|---|---|
| Architecture (surfaces, data flow) | Architecture overview |
| APIs, SDKs, CLI, MCP | REST API, SDKs, CLI, MCP |
| Rate limits and quotas | Rate limits & quotas |
| Webhooks and event delivery | Webhooks |
| Data portability / export | Portability & export |
| Data model / schema | Data model |
Responsible AI
| Question class | Where it’s answered |
|---|---|
| Model training on customer data | Responsible AI principle 03 |
| Explainability / citation trails | Responsible AI principle 02 |
| Human oversight / decision-maker attribution | Authentication & tiers, Responsible AI red lines |
| Model bias, drift, evaluation | Responsible AI, EU AI Act pack |
| Protected-category decisions (hiring, lending, medical) | Responsible AI red line 5 |
What’s available under NDA
Requestable at enterprise@nebbos.ai with a signed mutual NDA:
- SOC 2 Type II progress statement and gap remediation plan
- ISO 27001 substrate-controls attestation letter
- Full EU AI Act Annex IV technical documentation pack (current state)
- HIPAA readiness statement + BAA template
- Full penetration-test summary (redacted for exploit specifics)
- Standard security questionnaires pre-filled: CAIQ, SIG Core / SIG Lite, VSA-Full
- Insurance certificates (cyber liability, errors & omissions, general liability)
- Full BCP / DR document
- Full VPAT 2.5 (per-criterion)
- Reference customer list with authorization confirmation
What we won’t answer
Things we decline politely: questions that require exposing specific customer names or usage volumes without their authorization, questions that ask us to characterise other vendors’ security posture, and questions that request source code review outside a structured Nebbos-authorised review programme. When your procurement asks these, the honest answer is “we can’t ethically answer that from the vendor side; ask the customers directly / consult independent analysts / arrange a code-review engagement.”
Requesting the full response
For a full pre-filled response against your specific questionnaire (SIG Core, CAIQ, custom RFP), attach the questionnaire to your email to enterprise@nebbos.ai. Turnaround: 5 business days for a standard SIG/CAIQ, longer for custom RFPs.