Submitted by Northcrest Software · April 18, 2026 · 36 questions, 36 approved answers.
This packet is the Northcrest Software response to Harborside Pharmaceuticals’s vendor evaluation questionnaire. It consolidates 36 approved answers spanning Cover, Security, Technical, Compliance, and Pricing, plus the supporting exhibits enumerated in the appendix. Every answer has been reviewed by the named function owner and signed off by the executive approver prior to submission. The Order Form, master agreement, and signed exhibits are delivered alongside this PDF under the same submission record.
Manager notes — Lost — competitor offered embedded SDK at lower price point. ESG questions challenged us.
Encryption, identity, access control, incident response, and certifications. Each answer below is the approved Northcrest position of record, reviewed by Diego Ortega (security reviewer) against the trust portal documentation and SOC 2 / ISO 27001 evidence on file.
| Question | Buyer ask | Approved answer |
|---|---|---|
Q-1890-S01 Security | How is customer data encrypted at rest? | Northcrest answer to "How is customer data encrypted at rest?" — drafted from internal documentation and approved. |
Q-1890-S02 Security | Describe your incident response process. | Northcrest answer to "Describe your incident response process." — drafted from internal documentation and approved. |
Q-1890-S03 Security | Are you SOC 2 Type II certified? | Northcrest answer to "Are you SOC 2 Type II certified?" — drafted from internal documentation and approved. |
Q-1890-S04 Security | Do you support SAML SSO? | Northcrest answer to "Do you support SAML SSO?" — drafted from internal documentation and approved. |
Q-1890-S05 Security | What is your penetration testing cadence? | Northcrest answer to "What is your penetration testing cadence?" — drafted from internal documentation and approved. |
Q-1890-S06 Security | How is MFA enforced for admin actions? | Northcrest answer to "How is MFA enforced for admin actions?" — drafted from internal documentation and approved. |
Q-1890-S07 Security | How are administrative actions logged? | Northcrest answer to "How are administrative actions logged?" — drafted from internal documentation and approved. |
Q-1890-S08 Security | What is your network segmentation model? | Northcrest answer to "What is your network segmentation model?" — drafted from internal documentation and approved. |
Q-1890-S09 Security | Describe your vulnerability disclosure process. | Northcrest answer to "Describe your vulnerability disclosure process." — drafted from internal documentation and approved. |
Q-1890-S10 Security | How are customer encryption keys rotated? | Northcrest answer to "How are customer encryption keys rotated?" — drafted from internal documentation and approved. |
Q-1890-S11 Security | Do you support customer-managed keys? | Northcrest answer to "Do you support customer-managed keys?" — drafted from internal documentation and approved. |
Architecture, integrations, APIs, residency, and operational SLAs. Answers reflect the current production posture as of submission; performance characterizations are from the most recent quarterly load test and are reproducible in customer sandbox environments.
| Question | Buyer ask | Approved answer |
|---|---|---|
Q-1890-T12 Technical | Do you support custom fields? | Northcrest answer to "Do you support custom fields?" — drafted from internal documentation and approved. |
Q-1890-T13 Technical | Describe your audit/event stream. | Northcrest answer to "Describe your audit/event stream." — drafted from internal documentation and approved. |
Q-1890-T14 Technical | Do you support Slack notifications? | Northcrest answer to "Do you support Slack notifications?" — drafted from internal documentation and approved. |
Q-1890-T15 Technical | Describe your deployment architecture. | Northcrest answer to "Describe your deployment architecture." — drafted from internal documentation and approved. |
Q-1890-T16 Technical | Do you offer multi-region failover? | Northcrest answer to "Do you offer multi-region failover?" — drafted from internal documentation and approved. |
Q-1890-T17 Technical | What is your published uptime SLA? | Northcrest answer to "What is your published uptime SLA?" — drafted from internal documentation and approved. |
Q-1890-T18 Technical | Do you have a public API? | Northcrest answer to "Do you have a public API?" — drafted from internal documentation and approved. |
Q-1890-T19 Technical | What webhooks are supported? | Northcrest answer to "What webhooks are supported?" — drafted from internal documentation and approved. |
Q-1890-T20 Technical | Do you support Salesforce integration? | Northcrest answer to "Do you support Salesforce integration?" — drafted from internal documentation and approved. |
Q-1890-T21 Technical | What is your data residency story? | Northcrest answer to "What is your data residency story?" — drafted from internal documentation and approved. |
Q-1890-T22 Technical | Describe your API rate limits. | Northcrest answer to "Describe your API rate limits." — drafted from internal documentation and approved. |
Q-1890-T23 Technical | How do you handle large attachments? | Northcrest answer to "How do you handle large attachments?" — drafted from internal documentation and approved. |
GDPR, HIPAA, residency, retention, sub-processors, and data-subject-request handling. Reviewed by Sarah Kim (legal & compliance) against the Data Processing Agreement, Standard Contractual Clauses, and the published sub-processor list.
| Question | Buyer ask | Approved answer |
|---|---|---|
Q-1890-C29 Compliance | Schrems II — Standard Contractual Clauses in place? | Northcrest answer to "Schrems II — Standard Contractual Clauses in place?" — drafted from internal documentation and approved. |
Q-1890-C30 Compliance | Are you CCPA compliant? | Northcrest answer to "Are you CCPA compliant?" — drafted from internal documentation and approved. |
Q-1890-C31 Compliance | Are you GDPR compliant? | Northcrest answer to "Are you GDPR compliant?" — drafted from internal documentation and approved. |
Q-1890-C32 Compliance | Where is customer data stored? | Northcrest answer to "Where is customer data stored?" — drafted from internal documentation and approved. |
Q-1890-C33 Compliance | Do you support EU data residency? | Northcrest answer to "Do you support EU data residency?" — drafted from internal documentation and approved. |
Q-1890-C34 Compliance | Are you HIPAA compliant? | Northcrest answer to "Are you HIPAA compliant?" — drafted from internal documentation and approved. |
Q-1890-C35 Compliance | What is your data retention policy? | Northcrest answer to "What is your data retention policy?" — drafted from internal documentation and approved. |
Q-1890-C36 Compliance | How are sub-processors managed? | Northcrest answer to "How are sub-processors managed?" — drafted from internal documentation and approved. |
Tiers, volume discounts, payment terms, and price-cap protections. Pricing below is the Westfield Health quote position; the formal Order Form supersedes any discrepancies and is signed under the master agreement attached to this packet.
| Question | Buyer ask | Approved answer |
|---|---|---|
Q-1890-P24 Pricing | What is included in support pricing? | Northcrest answer to "What is included in support pricing?" — drafted from internal documentation and approved. |
Q-1890-P25 Pricing | How is your pricing structured? | Northcrest answer to "How is your pricing structured?" — drafted from internal documentation and approved. |
Q-1890-P26 Pricing | Are there volume discounts available? | Northcrest answer to "Are there volume discounts available?" — drafted from internal documentation and approved. |
Q-1890-P27 Pricing | What is included in the Enterprise tier? | Northcrest answer to "What is included in the Enterprise tier?" — drafted from internal documentation and approved. |
Q-1890-P28 Pricing | Are price increases capped at renewal? | Northcrest answer to "Are price increases capped at renewal?" — drafted from internal documentation and approved. |