Data and privacy
Can Grunt read or access data in our Excel and PowerPoint?
Can Grunt read or access data in our Excel and PowerPoint?
Does the supplier process any personal data on behalf of the client?
Does the supplier process any personal data on behalf of the client?
Is data stored or made available outside the EU/EEA?
Is data stored or made available outside the EU/EEA?
What is the retention period for the storage of data?
What is the retention period for the storage of data?
What type of cloud or hosting service does Grunt use?
What type of cloud or hosting service does Grunt use?
What is the tier level of the data centres used?
What is the tier level of the data centres used?
Which components of the service are shared with other customers?
Which components of the service are shared with other customers?
Security
Who is the responsible point of contact for information security?
Who is the responsible point of contact for information security?
Does Grunt have an information security management system?
Does Grunt have an information security management system?
Does Grunt have a methodology for carrying out risk assessments?
Does Grunt have a methodology for carrying out risk assessments?
Does Grunt have routines for follow-up of risk-reducing measures?
Does Grunt have routines for follow-up of risk-reducing measures?
Does Grunt have routines for when and how risk assessments are carried out?
Does Grunt have routines for when and how risk assessments are carried out?
Does Grunt inform clients if vulnerabilities are identified?
Does Grunt inform clients if vulnerabilities are identified?
How frequently are security policies reviewed and updated?
How frequently are security policies reviewed and updated?
Describe your data encryption requirements and key management
Describe your data encryption requirements and key management
Describe your network defences
Describe your network defences
Has Grunt run a penetration test to assess vulnerabilities?
Has Grunt run a penetration test to assess vulnerabilities?
Do you have evidence of a code scan process?
Do you have evidence of a code scan process?
Does Grunt have routines for handling security breaches?
Does Grunt have routines for handling security breaches?
Does Grunt have routines for incident notification without unjustified delay?
Does Grunt have routines for incident notification without unjustified delay?
Can security logs be transferred to the customer on request?
Can security logs be transferred to the customer on request?
Do you have SSO?
Do you have SSO?
Does Grunt require disabling Defender or other security features?
Does Grunt require disabling Defender or other security features?
Employee policies
What safety procedures exist for employment and when people leave?
What safety procedures exist for employment and when people leave?
Is a security training and awareness program in place for all employees?
Is a security training and awareness program in place for all employees?
Access control
How are access rights allocated, revised, and deleted?
How are access rights allocated, revised, and deleted?
What routines exist for remote access and use of mobile devices?
What routines exist for remote access and use of mobile devices?
Is automatic logging of logins and system access implemented?
Is automatic logging of logins and system access implemented?
How do you track employees with access to client systems and information?
How do you track employees with access to client systems and information?
Can Grunt provide a formal overview of access to client systems on request?
Can Grunt provide a formal overview of access to client systems on request?
Operations
Does Grunt have operating documentation and routines for maintaining it?
Does Grunt have operating documentation and routines for maintaining it?
Does Grunt have routines for change management?
Does Grunt have routines for change management?
Does Grunt have routines for incident handling?
Does Grunt have routines for incident handling?
Does Grunt have routines for backup?
Does Grunt have routines for backup?
Does Grunt regularly test restores from backup?
Does Grunt regularly test restores from backup?
Does Grunt have routines for logging and monitoring?
Does Grunt have routines for logging and monitoring?
What encryption routines are in place between systems?
What encryption routines are in place between systems?
Does Grunt have continuity plans?
Does Grunt have continuity plans?
How are continuity plans maintained and tested?
How are continuity plans maintained and tested?
Does Grunt have routines for secure system development?
Does Grunt have routines for secure system development?
Does Grunt have routines for the follow-up of its suppliers?
Does Grunt have routines for the follow-up of its suppliers?
Does Grunt verify that subcontractors comply with client requirements?
Does Grunt verify that subcontractors comply with client requirements?
Does the service include API access? Is it authenticated and encrypted?
Does the service include API access? Is it authenticated and encrypted?
Does the application support role-based access?
Does the application support role-based access?
Does your service support web services? REST or SOAP?
Does your service support web services? REST or SOAP?
Do you conduct source code scanning with automated tools?
Do you conduct source code scanning with automated tools?
Physical security and continuity
How does Grunt handle physical threats like power cuts?
How does Grunt handle physical threats like power cuts?
Does Grunt have routines for the destruction of storage media?
Does Grunt have routines for the destruction of storage media?
License management
How are licenses handled?
How are licenses handled?
How do you manage distribution? Can Grunt be packaged and pushed?
How do you manage distribution? Can Grunt be packaged and pushed?
- MSI file is distributed to your IT team
- Installation can be automated using common tools and configured with command line arguments
- Grunt is installed to Program Files
- Updates are distributed to your IT team according to your agreement (typically monthly or every other month)
- Users can see that new versions are available but cannot upgrade themselves
- Installation from MSI file (from IT or by the user manually)
- Grunt is installed without administrative rights to the user’s AppData folder
- New updates are made available online and the user is offered to update the next time they open PowerPoint
- The upgrade completes within 15 seconds
- New versions are normally available once a month
Terminology
What is a 'tenant' in Grunt's context?
What is a 'tenant' in Grunt's context?
What is the 'Content Library'?
What is the 'Content Library'?
System requirements
Is 32-bit Windows supported?
Is 32-bit Windows supported?
Does Grunt increase PowerPoint's memory usage?
Does Grunt increase PowerPoint's memory usage?
Certifications and compliance
Is Grunt certified according to ISO/IEC 27001 or other standards?
Is Grunt certified according to ISO/IEC 27001 or other standards?
Does Grunt comply with applicable regulations?
Does Grunt comply with applicable regulations?
Does Grunt have routines for notifications to the Norwegian Data Protection Authority?
Does Grunt have routines for notifications to the Norwegian Data Protection Authority?
Does Grunt have routines for notifying the client if there is no basis for processing personal data?
Does Grunt have routines for notifying the client if there is no basis for processing personal data?