Skip to Content
ProductRFP / RFI response

RFP / RFI response guide

Most procurement questionnaires ask the same questions. This page names what Nebbos has already answered publicly (so your procurement team doesn’t need to ask us), what’s available under NDA, and what to request when the public docs don’t cover it.

What’s already answered publicly

Point your procurement team at these pages directly. Every question below is a section on that page, so a copy-paste into an RFP response is a fifteen-minute exercise.

Security & compliance

Question classWhere it’s answered
Encryption at rest / in transitProduct datasheet → Security controls
Key management (KMS, HSM, secure element)Product datasheet, Cradle provisioning
Access control model (RBAC, ABAC, tier)Authentication & tiers
Row-level isolation / multi-tenant separationRow-level isolation
SOC 2 / ISO 27001 / HIPAA / GDPR / EU AI ActCompliance posture
Audit logging and log tamper-resistanceThe audit chain
Vulnerability disclosure and bug bountyVulnerability disclosure
Accessibility (WCAG, Section 508, VPAT)Accessibility (VPAT)
Business continuity / disaster recoveryBusiness continuity & DR
Subprocessors and data flowSubprocessor list

Operations & support

Question classWhere it’s answered
Uptime SLA and service creditsSLA
Response times by severitySLA, Incident response
Incident communication commitmentIncident response
Public system status boardSystem statusstatus.nebbos.ai 
Change management (deprecation, versioning)Versioning & changelog, Deprecation policy

Product & integration

Question classWhere it’s answered
Architecture (surfaces, data flow)Architecture overview
APIs, SDKs, CLI, MCPREST API, SDKs, CLI, MCP
Rate limits and quotasRate limits & quotas
Webhooks and event deliveryWebhooks
Data portability / exportPortability & export
Data model / schemaData model

Responsible AI

Question classWhere it’s answered
Model training on customer dataResponsible AI principle 03
Explainability / citation trailsResponsible AI principle 02
Human oversight / decision-maker attributionAuthentication & tiers, Responsible AI red lines
Model bias, drift, evaluationResponsible AI, EU AI Act pack
Protected-category decisions (hiring, lending, medical)Responsible AI red line 5

What’s available under NDA

Requestable at enterprise@nebbos.ai with a signed mutual NDA:

  • SOC 2 Type II progress statement and gap remediation plan
  • ISO 27001 substrate-controls attestation letter
  • Full EU AI Act Annex IV technical documentation pack (current state)
  • HIPAA readiness statement + BAA template
  • Full penetration-test summary (redacted for exploit specifics)
  • Standard security questionnaires pre-filled: CAIQ, SIG Core / SIG Lite, VSA-Full
  • Insurance certificates (cyber liability, errors & omissions, general liability)
  • Full BCP / DR document
  • Full VPAT 2.5 (per-criterion)
  • Reference customer list with authorization confirmation

What we won’t answer

Things we decline politely: questions that require exposing specific customer names or usage volumes without their authorization, questions that ask us to characterise other vendors’ security posture, and questions that request source code review outside a structured Nebbos-authorised review programme. When your procurement asks these, the honest answer is “we can’t ethically answer that from the vendor side; ask the customers directly / consult independent analysts / arrange a code-review engagement.”

Requesting the full response

For a full pre-filled response against your specific questionnaire (SIG Core, CAIQ, custom RFP), attach the questionnaire to your email to enterprise@nebbos.ai. Turnaround: 5 business days for a standard SIG/CAIQ, longer for custom RFPs.