- Job title
- Technical service technician
- Sector
- Jewelry
- Organization type
- 120-person company
- Joined
- Dec 2025
- Message
- 336
We're about to close a $55,000/year B2B SaaS deal with an enterprise client based in the US. Our company is Delaware-registered, our dev team has 7 people, and our entire infrastructure runs on AWS. Before signing, the client's risk assessment team sent over a comprehensive checklist, and one of the requirements is sharing our 'AWS Security Audit Policy' document.
Frankly, our security groups are configured, S3 buckets are private, and our database is encrypted. But we don't have an official written document titled 'AWS Security Audit Policy'. Is the auditor expecting a technical IAM permission template, or a corporate governance policy document?
What is the minimum content this document should cover, and who internally should draft it? We have to turn this in within two weeks and have no idea where to start.