You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardexpand all lines: security.md
+31
Original file line number
Diff line number
Diff line change
@@ -41,3 +41,34 @@ We are working to identify and coordinate security efforts across the Jupyter co
41
41
The [Jupyter Security](https://github.com/jupyter/security) GitHub repo has information how to participate and contribute.
42
42
For discussion, please use the special Discourse [security topic](https://discourse.jupyter.org/c/special-topics/security/48) on the Jupyter Discourse server.
43
43
44
+
45
+
## vendor assessments
46
+
47
+
Jupyter cannot provide, or fill in "Plan-Risk Assessment", "Hecvat", "Vpat" and
48
+
similar vendor assessing questionnaire.
49
+
50
+
You likely have been redirected to this section after contacting the Jupyter
51
+
security team to fill in a questionnaire about the security best practice of your
52
+
Jupyter "vendor", and to assess the Jupyter "product".
53
+
54
+
The Jupyter Team and Jupyter Security team are not vendors, and cannot act as
55
+
a vendor. To be a vendor Jupyter would need to have a contractual relationship
56
+
with you, which we do not have.
57
+
58
+
Your questionnaire also likely ask how your 'vendor' store your informations
59
+
(user information, billing information, contact...); who has access to it; and
60
+
how they are vetted... etc. The Jupyter team does not have any contact or
61
+
billing information; nor do we collect; store or have access to any of the
62
+
information about how your Jupyter user use Jupyter, or what they do in Jupyter;
63
+
the Jupyter Team is not aware either of who installs Jupyter.
64
+
65
+
- If you use a service provider for Jupyter; they are your vendor, and can
66
+
answer those questions.
67
+
68
+
- If you self-host Jupyter, then it is likely to your IT team to fill in those
69
+
assessment as all the data is controlled by your IT team.
70
+
71
+
- If you still do need a vendor assessment we advise you to contact one of the
72
+
many companies that provide Jupyter support; We cannot unfortunately give you
0 commit comments