Definition
应如何考察一家数字产品护照供应商?
请验证符合性,而不是验证证书。签发一份护照,把输出直接对照 GS1 Digital Link、EPCIS 2.0 与 W3C Verifiable Credentials 规范逐项核对。这类证据无需信任厂商或审计方,而且检验的正是真正决定您的数据能否保持可迁移的那部分。
Certificates still matter for a security review, but ask for the scope statement before the certificate. A boundary that excludes the platform holding your data is the most common way a genuine certificate turns out to be irrelevant.
证据
什么内容有什么样的证据
| What you want to establish | How to get it | Needs us? |
|---|---|---|
| GS1 Digital Link conformance | Issue a passport and check the identifier resolves per the specification | A sandbox key only |
| EPCIS 2.0 conformance | Append an event and validate the JSON-LD against the standard | A sandbox key only |
| Credential verifiability | Verify a signed credential with any conforming W3C library | No — that is the point |
| Data portability on exit | Export and confirm the documents are standards-conformant | A sandbox key only |
| Security controls | Send your vendor questionnaire; we complete it against your controls | Yes |
| Formal certification status | Ask during procurement — we will tell you exactly where it stands | Yes |
符合性
我们所实现的规范
答疑
常见问题
你们持有 SOC 2 或 ISO 27001 吗?
这不是我们会在网页上宣称的东西。正式鉴证在我们的规划之中,每取得一项认证,我们都会在此发布,并附上认证机构、适用范围声明与有效期。在此之前,请在采购环节直接询问我们,您会得到关于现状的直接回答。
为什么覆盖范围比证书本身更重要?
因为证书说明的是针对某个既定范围做过一次审计,而范围才是关键所在。一份覆盖企业 IT 职能的证书,几乎无法说明保存贵方护照数据的那个平台。无论评估对象是谁,都请追问范围声明究竟点名了哪些系统。
GDPR 是一种认证吗?
不是。它是一项法律义务,而非经审核的认证体系,所以「通过 GDPR 认证」这句话由谁说出来都没有意义。真正能拿出证据的,是数据处理条款、次级处理方清单、跨境传输机制以及背后的安全措施 —— 这些我们都会提供。
完全不与你们接触的情况下,我能验证什么?
对标准的符合性。用沙箱密钥签发一份护照,把输出直接对照 GS1 Digital Link、EPCIS 2.0 与 W3C Verifiable Credentials 的规范逐条核对。这比一枚徽章更有力,因为它既不依赖于信任我们,也不依赖于信任某位审计人。
在此期间我们该如何评估你们?
Send your vendor questionnaire to ceo@fistasolutions.com. We will complete it against your specific controls, and where the honest answer is that something is not yet in place we will say so rather than answering around it. That is more useful to a security reviewer than a badge would be.