For your vendor-assessment form. Copy these answers into your questionnaire, or print this page and attach it.

AccessPoint — Vendor Questionnaire Answers

The questions vendor-assessment and security questionnaires ask most, pre-answered. If your form asks something not covered here, send it over and we'll complete it.

Vendor: Realizer Services Inc. · Product: AccessPoint · Last reviewed: August 2026

Company

QuestionAnswer
Legal nameRealizer Services Inc.
Founded / headquarters2019 · Nova Scotia, Canada
ProductAccessPoint — the Microsoft 365-native platform for public-sector access, privacy, and responsible AI.
PartnershipsMicrosoft Partner; AccessPoint is reviewed and tested by Microsoft as part of the AppSource submission process before listing on the Microsoft commercial marketplace.

Hosting & data residency

QuestionAnswer
Where is the application hosted?In the customer's own Microsoft 365 tenant and Azure subscription. The vendor operates no hosting environment for customer data.
Where is customer data stored?Entirely within the customer's tenant, in the Azure region the customer selects at deployment. Data never leaves the customer's environment.
Does the vendor have access to customer data?No. The vendor has no runtime access to the customer's deployment and holds no copy of customer data.
What subprocessors are used?None. No vendor-side systems store or process customer content.
Are there cross-border data transfers?The product initiates none. Data residency follows the customer's own Microsoft 365 and Azure configuration.

Security

QuestionAnswer
Encryption in transitTLS 1.3.
Encryption at restMicrosoft 365 and Azure platform encryption, within the customer's own environment.
Authentication / SSOMicrosoft Entra ID only — no separate accounts or passwords. The customer's MFA and Conditional Access policies apply in full.
AuthorizationGranular, tenant-configurable role-based access control enforced server-side on every request, plus a PII firewall separating custodians and contributors from requestor and data-subject identity.
Audit loggingEvery action across every module is written to an append-only, hash-chained audit ledger with integrity verification, exportable as court-ready evidence.
Security monitoringRuns inside the customer's security boundary, so the customer's Microsoft Defender for Cloud, Sentinel, and Purview govern it like any other workload.
Hardening defaultsEntra-only database authentication (no SQL credentials exist), Microsoft Defender for SQL on by default, FTPS and basic authentication disabled from first deployment.
Software supply-chain integrityThe deployment script verifies the published SHA-256 hash of every artifact and aborts on mismatch. Updates are distributed through the Microsoft marketplace channel and applied on the customer's schedule.

Compliance

QuestionAnswer
SOC 2 / ISO 27001 certification?Not applicable to this deployment model: those certifications attest to how a vendor protects data hosted in its own cloud, and AccessPoint holds no customer data. The equivalent assurance derives from the customer's own Microsoft 365 and Azure environment, which Microsoft certifies extensively.
Standards alignmentITSG-33 control mapping, GC Cloud Guardrails, GDPR Article 30 (built-in ROPA), ISO 31000 (risk register methodology). Detail: government security controls guide.
AccessibilityWCAG 2.1 AA is the standard the product and this website are designed against. A self-assessed Accessibility Conformance Report for the application (VPAT® format; static code review, independent adversarial verification, and runtime browser verification, with accessibility linting enforced in CI) is published; a third-party accessibility audit has not yet been performed. See also the accessibility statement.

AI use

QuestionAnswer
Does the product use AI?Only if the customer chooses to deploy the optional AI Assist, which provisions an Azure OpenAI resource in the customer's own subscription and region. Microsoft does not train models on customer content; prompt and response content is never stored; every output is a suggestion a person decides on; a customer-controlled monthly token budget hard-stops all AI processing; and an administrator acknowledges the terms once per tenant, recorded with user and date.

Continuity, support & exit

QuestionAnswer
Backup and disaster recoveryAll data resides in the customer's Microsoft 365 and Azure environment, so the customer's existing backup and recovery practices apply directly. There is no vendor cloud to recover from.
SupportVia realizer.io/support; we respond within one business day. Optional guided setup, training, and consulting are available as services.
Data return on exitA business-readable export of everything is available to the customer at any time, in one click — and the data never left the customer's environment in the first place. How export works.
Contract exitCancel the marketplace subscription from your Microsoft admin center. Nothing needs to be unwound or repatriated.
Source: www.realizer.io/procurement/vendor-questionnaire · Part of the AccessPoint procurement pack · Full questionnaires and RFP question sets: send them to us and we'll complete them.