DEXTRA ASSURANCEOPS · FOR SOFTWARE AND SERVICE SUPPLIERS

Know exactly what's inside the security assurance evidence package before you ask for one.

A Dextra AssuranceOps evidence package is a bounded case: a question set agreed before paid work begins, a governed progression from diagnostic through review, and a final response your own named reviewer approves — not THONIS.

Your own named reviewer approves what goes back to your buyer. THONIS Systems never signs, attests, or approves on your behalf.

Not ready to scope a case yet? See the Dextra AssuranceOps platform.

A buyer's security review is stalled behind one hard question.

Your buyer sent a questionnaire. Somewhere in it is a question your approved answers do not cleanly cover — a product, environment, or use case the existing library was not written for.

Before you commit to anything, you should be able to see exactly what a Dextra AssuranceOps case gives you: what is agreed up front, what stays visible while the case is open, and who signs off at the end.

What you receive before you commit to anything.

SCOPE

A bounded question set

Before any paid work begins, you and THONIS agree the exact question set the case will cover.

INTAKE

CSV or text import

The questionnaire your buyer already sent you can be imported as a CSV file or as plain text.

Every case sits in exactly one stage at a time.

01

Diagnostic

The case opens around the exact question set the buyer needs answered.

02

Scoping

The bounded question set is agreed and locked before any paid work begins.

03

Investigating

Evidence is connected to each question. A question with nothing connected to it stays visibly open.

04

Drafting

A response takes shape against the connected evidence, ready for line-by-line review.

05

Reviewing

Your named reviewer approves the exact response and the evidence behind it, through AssuranceOps's decision kernel.

The record does not move once a determination is made.

EVIDENCE BINDING

Approval binds to its evidence

Your named reviewer's approval and the response delivered to your buyer both move through AssuranceOps's decision kernel, which binds the approved result to the evidence it relied on.

IMMUTABLE

Determinations do not get rewritten

Once your named reviewer records a determination, it cannot be quietly edited. A changed fact opens a new, dated determination instead of altering the old one.

RETAINED HISTORY

The decision stays reconstructable

Every scoping choice, evidence link, and approval stays part of the case record, so the exact basis for a decision can be reconstructed later.

Your named reviewer decides. THONIS never signs, attests, or approves.

AssuranceOps keeps the scoped questions, the connected evidence, the draft response, and the approval record together in one case. The judgment on that response always belongs to the named reviewer your own organization designates as accountable.

THONIS Systems does not sign the response, does not attest to its accuracy, and does not approve it on your behalf. THONIS does not claim that any buyer, assessor, certification body, or auditor accepts the result — that decision belongs to the party who receives it.

Ask for the security assurance evidence package.

Describe the buyer, the product or service in scope, and the deadline you are working against. THONIS will confirm whether a bounded case can be scoped before any paid work begins.

Ask for the evidence package