# VENTEX Connect — public procurement checklist

Updated: 30 August 2026  
Purpose: Structured preliminary review before evaluation or procurement

> This checklist is a working aid. It is not a certification, audit, approval, contractual offer or security guarantee. Organisation-specific architecture, privacy, contract and risk review remains necessary.

## 1. Product status and scope

- [ ] Read the current product definition and documented operating boundaries
- [ ] Review the Release Centre and dated change history
- [ ] Define evaluation scope, stop criteria and success criteria

## 2. Architecture and protection paths

- [ ] Review identity, session and role model
- [ ] Review message, file and key boundaries
- [ ] Understand remaining metadata and explicit non-claims

## 3. Deployment and responsibility

- [ ] Define operating model and responsibility boundaries
- [ ] Review infrastructure, integration and backup requirements
- [ ] Plan fallback channels, recovery and service outage response

## 4. Evidence and external review

- [ ] Review the claim ledger including technical basis and boundary
- [ ] Document responsible-disclosure and escalation routes
- [ ] Distinguish internal evidence from external audit or certification

## 5. Privacy and contract

- [ ] Evaluate roles, data categories and legal bases
- [ ] Define data minimisation and retention for the evaluation
- [ ] Obtain contractual, privacy and organisation-specific approvals

## Public review routes

- Evidence Center: https://www.ventex-connect.com/en/evidence
- Security Control Room: https://www.ventex-connect.com/en/security-control-room
- Release Centre: https://www.ventex-connect.com/en/updates
- Deployment Planner: https://www.ventex-connect.com/en/deployment-planner
- Resilience Lab: https://www.ventex-connect.com/en/resilience-lab
- Responsible Disclosure: https://www.ventex-connect.com/en/security/disclosure
- Trust Center: https://trust.ventex-connect.com/en
- System status: https://status.ventex-connect.com/en
