SemantiqWall
PT EN
Sign in I'm a vendor
Public criteria

What a vendor has to show to get verified

The same 12 criteria for every vendor. Each answer comes with evidence and is accepted, sent back for changes or rejected by a reviewer with no ties to the vendor.

The criteria draw on the OWASP ASVS (the open Application Security Verification Standard) and on US state privacy laws (with California's CCPA as the reference), written in the language of the buyer.

The same criteria apply in both countries; only the law cited and the expected evidence change.

1

Identified company

Question for the vendor: Provide the legal name, the state where the company is registered, the address and who is legally responsible for the company.

Why it matters: You need to know who you are signing with and who to hold accountable if something goes wrong.

Expected evidence: Certificate from the Secretary of State of the state of registration (Certificate of Good Standing or Articles of Incorporation/Organization).

2

Data collected and purpose

Question for the vendor: Which data about your customer's customers does the system receive and store, and what is each item used for?

Why it matters: A vendor that can't say what data it stores can't protect it either.

Expected evidence: Data inventory, privacy policy excerpt or documentation.

3

Where data is stored and how it is protected

Question for the vendor: Which provider and country is the data stored in? Is it encrypted in transit and at rest?

Why it matters: Data stored without encryption, or in a place nobody can name, is the first to leak.

Expected evidence: Screenshot of the provider configuration, technical report or architecture documentation.

4

Who on the team has access

Question for the vendor: Who on your team can see customer data? Are there individual logins, two-step verification and a record of who accessed what?

Why it matters: Most data leaks start with a shared password or access that nobody reviews.

Expected evidence: Screenshot of the access policy, the list of roles or the access log (without personal data).

5

Tested backup

Question for the vendor: How often is data backed up, where is the backup stored and when was the last restore test?

Why it matters: A backup that has never been restored is a promise, not a guarantee.

Expected evidence: Screenshot of the backup routine and a record of the last restore test.

6

Incident plan

Question for the vendor: If there's a leak or breach, what happens, how quickly is the customer notified and who notifies the authorities required by state breach notification laws?

Why it matters: Every US state has a breach notification law, with different deadlines and authorities. Your vendor needs to know the path before it's needed.

Expected evidence: Incident response plan or contract clause.

7

Privacy: state laws and contract

Question for the vendor: Who is responsible for privacy, and how can they be reached? Is there a service provider contract under the CCPA and state laws? How do you handle consumer requests (to know, correct, delete, not sell or share)? Do you honor the Global Privacy Control signal?

Why it matters: Under US state privacy laws, the contract with a service provider must limit the use of the data to the contracted service. Without that contract, handing over the data may no longer be treated as a service.

Expected evidence: Link to the privacy policy and the data processing contract template (DPA or service provider addendum).

8

Third parties that receive the data

Question for the vendor: List the third-party services that receive customer data (cloud, AI, messaging, email, payments).

Why it matters: Your data may be passing through companies you never hired.

Expected evidence: Subprocessor list, published or sent to the customer.

9

Use of artificial intelligence

Question for the vendor: Does the system use third-party AI models? Is customer data used to train models? What can the AI agents do on their own (look up, send, delete), and what controls those actions?

Why it matters: An AI agent doesn't just chat: it takes actions in your systems. You need to know what it can do without anyone approving.

Expected evidence: Documentation of the AI flow, the AI provider's terms, and the policy that controls actions. · Accepts "not applicable", with a reviewed justification.

10

WhatsApp through the official API

Question for the vendor: Does the WhatsApp integration use Meta's official API (Cloud API or an official provider)? If not, what technology does it use?

Why it matters: An unofficial connection (via QR code or automated WhatsApp Web) violates Meta's terms, can get the company's number banned and exposes conversations.

Expected evidence: Screenshot of WhatsApp Business Manager (account and number) or a contract with an official provider. · Accepts "not applicable", with a reviewed justification.

11

Contract exit

Question for the vendor: When the contract ends, how does the customer export the data and how soon is it deleted?

Why it matters: Switching systems shouldn't mean losing your data or leaving it behind.

Expected evidence: Contract clause or documented procedure.

12

Security contact and testing

Question for the vendor: Is there a public channel for reporting security vulnerabilities? When was the system's last security test and what was fixed?

Why it matters: Every system has flaws. What sets serious vendors apart is a channel to hear about them and a routine to fix them.

Expected evidence: Link to security.txt or the security page and a summary of the last test; SOC 2 report or ISO 27001 certificate, if any.

Verification rules

Independence

Reviewers can't have ties to the vendor. The system checks and blocks it. SemantiqWall is built by ZapBrabo Technology, which owns ZapBrabo: ZapBrabo goes through the same criteria, reviewed by an outsider.

All or nothing

A vendor only becomes "verified" with every criterion accepted. An answer changed after acceptance goes back to review, and the vendor loses the level until it's reviewed again.

Valid for 12 months

After that, the verification expires on its own and the vendor confirms everything again. The public profile shows the date of each item.

Domain proven

No one can answer on behalf of a website without proving they own the domain, with a DNS record or a file on the site itself.

Not a full certification

Verification shows the vendor has answers and evidence for each criterion. It doesn't guarantee nothing will ever go wrong. Level 3 adds real monitoring of AI agents.

Honest public lookup

Level 1 only uses public information and says what it couldn't verify. Missing data never shows up as protection.

I'm a vendor: I want to be assessed

Leave your contact info. Our team creates your company's access to SemantiqWall. There you prove your domain, answer the criteria with evidence and follow the review.

  • Verified vendor badge for your website and sales proposals
  • See how many companies looked you up
  • Level 3 for those using AI agents