Skip to content

Commit 79bd1fa

Browse files
authored
Add a vendor assessement to the security page. (#774)
1 parent 82a1b35 commit 79bd1fa

File tree

1 file changed

+31
-0
lines changed

1 file changed

+31
-0
lines changed

security.md

+31
Original file line numberDiff line numberDiff line change
@@ -41,3 +41,34 @@ We are working to identify and coordinate security efforts across the Jupyter co
4141
The [Jupyter Security](https://github.com/jupyter/security) GitHub repo has information how to participate and contribute.
4242
For discussion, please use the special Discourse [security topic](https://discourse.jupyter.org/c/special-topics/security/48) on the Jupyter Discourse server.
4343

44+
45+
## vendor assessments
46+
47+
Jupyter cannot provide, or fill in "Plan-Risk Assessment", "Hecvat", "Vpat" and
48+
similar vendor assessing questionnaire.
49+
50+
You likely have been redirected to this section after contacting the Jupyter
51+
security team to fill in a questionnaire about the security best practice of your
52+
Jupyter "vendor", and to assess the Jupyter "product".
53+
54+
The Jupyter Team and Jupyter Security team are not vendors, and cannot act as
55+
a vendor. To be a vendor Jupyter would need to have a contractual relationship
56+
with you, which we do not have.
57+
58+
Your questionnaire also likely ask how your 'vendor' store your informations
59+
(user information, billing information, contact...); who has access to it; and
60+
how they are vetted... etc. The Jupyter team does not have any contact or
61+
billing information; nor do we collect; store or have access to any of the
62+
information about how your Jupyter user use Jupyter, or what they do in Jupyter;
63+
the Jupyter Team is not aware either of who installs Jupyter.
64+
65+
- If you use a service provider for Jupyter; they are your vendor, and can
66+
answer those questions.
67+
68+
- If you self-host Jupyter, then it is likely to your IT team to fill in those
69+
assessment as all the data is controlled by your IT team.
70+
71+
- If you still do need a vendor assessment we advise you to contact one of the
72+
many companies that provide Jupyter support; We cannot unfortunately give you
73+
names out of fairness.
74+

0 commit comments

Comments
 (0)