The same 12 criteria for every vendor. Each answer comes with evidence and is accepted, sent back for changes or rejected by a reviewer with no ties to the vendor.
The criteria are inspired by the OWASP ASVS (an open application security verification standard) and by the requirements of the LGPD (Brazil's data protection law), written in the language of the people who buy software.
The same criteria apply in both countries; only the law cited and the expected evidence change.
1
Identified company
Question for the vendor: Provide the legal company name, CNPJ (Brazilian company ID), address and who is legally responsible for the company.
Why it matters: You need to know who you are signing with and who to hold accountable if something goes wrong.
Expected evidence: CNPJ registration certificate or articles of incorporation.
2
Data collected and purpose
Question for the vendor: Which data about your customer's customers does the system receive and store, and what is each item used for?
Why it matters: A vendor that can't say what data it stores can't protect it either.
Expected evidence: Data inventory, privacy policy excerpt or documentation.
3
Where data is stored and how it is protected
Question for the vendor: Which provider and country is the data stored in? Is it encrypted in transit and at rest?
Why it matters: Data stored without encryption, or in a place nobody can name, is the first to leak.
Expected evidence: Screenshot of the provider configuration, technical report or architecture documentation.
4
Who on the team has access
Question for the vendor: Who on your team can see customer data? Are there individual logins, two-step verification and a record of who accessed what?
Why it matters: Most data leaks start with a shared password or access that nobody reviews.
Expected evidence: Screenshot of the access policy, the list of roles or the access log (without personal data).
5
Tested backup
Question for the vendor: How often is data backed up, where is the backup stored and when was the last restore test?
Why it matters: A backup that has never been restored is a promise, not a guarantee.
Expected evidence: Screenshot of the backup routine and a record of the last restore test.
6
Incident plan
Question for the vendor: If there is a data leak or breach, what happens, how quickly is the customer notified and who notifies the ANPD (Brazil's data protection authority)?
Why it matters: Under ANPD rules, an incident with relevant risk must be reported within a short deadline. Your vendor needs to know the process before it is needed.
Expected evidence: Incident response plan or contract clause.
7
LGPD: DPO and contract
Question for the vendor: Who is the data protection officer (DPO) and how can they be reached? Is there a contract or data processing agreement with the customer? How are data subject requests (access, correction, deletion) handled?
Why it matters: Under the LGPD (Brazil's data protection law), your company is jointly liable for what the vendor does with your customers' data.
Expected evidence: Link to the privacy policy, contract template or data processing agreement.
8
Third parties that receive the data
Question for the vendor: List the third-party services that receive customer data (cloud, AI, messaging, email, payments).
Why it matters: Your data may be passing through companies you never hired.
Expected evidence: List of subprocessors, published or sent to the customer.
9
Use of artificial intelligence
Question for the vendor: Does the system use third-party AI models? Is customer data used to train models? What can the AI agents do on their own (look up, send, delete), and what controls those actions?
Why it matters: An AI agent doesn't just chat: it takes actions in your systems. You need to know what it can do without anyone approving.
Expected evidence: Documentation of the AI flow, the AI provider's terms, and the policy that controls actions. · Accepts "not applicable", with a reviewed justification.
10
WhatsApp through the official API
Question for the vendor: Does the WhatsApp integration use Meta's official API (Cloud API or an official provider)? If not, what technology does it use?
Why it matters: An unofficial connection (via QR code or automated WhatsApp Web) violates Meta's terms, can get the company's number banned and exposes conversations.
Expected evidence: Screenshot of WhatsApp Business Manager (account and number) or a contract with an official provider. · Accepts "not applicable", with a reviewed justification.
11
Contract exit
Question for the vendor: When the contract ends, how does the customer export the data and how soon is it deleted?
Why it matters: Switching systems shouldn't mean losing your data or leaving it behind.
Expected evidence: Contract clause or documented procedure.
12
Security contact and testing
Question for the vendor: Is there a public channel for reporting security vulnerabilities? When was the system's last security test and what was fixed?
Why it matters: Every system has flaws. What sets serious vendors apart is a channel to hear about them and a routine to fix them.
Expected evidence: Link to security.txt or the security page, and a summary of the last test.
Verification rules
Independence
Reviewers can't have ties to the vendor. The system checks and blocks it. SemantiqWall is built by ZapBrabo Technology, which owns ZapBrabo: ZapBrabo goes through the same criteria, reviewed by an outsider.
All or nothing
A vendor only becomes "verified" with every criterion accepted. An answer changed after acceptance goes back to review, and the vendor loses the level until it's reviewed again.
Valid for 12 months
After that, the verification expires on its own and the vendor confirms everything again. The public profile shows the date of each item.
Domain proven
No one can answer on behalf of a website without proving they own the domain, with a DNS record or a file on the site itself.
Not a full certification
Verification shows the vendor has answers and evidence for each criterion. It doesn't guarantee nothing will ever go wrong. Level 3 adds real monitoring of AI agents.
Honest public lookup
Level 1 only uses public information and says what it couldn't verify. Missing data never shows up as protection.
I'm a vendor: I want to be assessed
Leave your contact info. Our team creates your company's access to SemantiqWall. There you prove your domain, answer the criteria with evidence and follow the review.
Verified vendor badge for your website and sales proposals