> For the complete documentation index, see [llms.txt](https://docs.glesys.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.glesys.com/security/security-measures/supply-chain-security.md).

# Supply chain security

Glesys manages supplier relationships to reduce cybersecurity risk and ensures that relevant security requirements are considered during selection, contracting, and ongoing monitoring.

### Key elements:

* **Supplier categorization:** Suppliers are categorized (e.g., Critical/Managed/Non-critical), including “information security-critical” suppliers, with defined oversight expectations.
* **Procurement security requirements:** For relevant procurements, requirements may include MFA, encryption, logging/monitoring, incident notification, data location/transfers, and assurance (e.g., ISO 27001/SOC2).
* **Offboarding controls:** Data return/deletion, access revocation, and secure disposal expectations are defined for security-critical supplier termination.
