General FAQs

General FAQs General Questionnaire FAQs
Why does the Welcome login screen show both the Meditology and CORL logos?
We are in the process of launching a portal for Corl's sister company, Meditology. Since Meditology and CORL have many of the same clients, we wanted to provide the best possible user experience. By providing a single authentication solution, you will have a single set of credentials across all our product and service platforms.
Does this single sign on have any impact on my data?
Not to worry. Even though we have just one sign on, your organization's data is segregated by application. There's no change to where your data is stored, and we only ever use your data for the purposes that you authorized.
Who is CORL Technologies?

CORL Technologies provides vendor security assessment services as an extension of our client’s internal resources. We work closely with our clients to prioritize and streamline the assessment process and recommend risk mitigation strategies to lower vendor risk.

What data does CORL collect?
CORL collects information to help clients understand vendor protections in alignment with regulatory and internal security requirements. This data is used to understand your security compared to regulatory privacy and security requirements and industry best practice.
Is my data held securely?
Yes. We have a contractual obligation to our clients to secure the information that you provide in response to this assessment. Vendor information is stored on CORL's servers located in a secure data center within the United States. Procedural and technical safeguards deployed at CORL include industry best practices and have been validated for SOC 2 Type 2 and align with HITRUST.
Will CORL need access to my systems or client data?
No. CORL bases vendor security assessments on the information shared directly by you. There is no requirement for CORL to directly access your systems or to review client data that may be housed with your organization.
Is my data shared with your client?
Data collected to assess a vendor’s security posture is collected for our client and used in assessing risk and determining risk remediation recommendations. The detailed data collected during that process may be shared or discussed with the client as needed to provide clarification of an identified deficiency or remediation recommendation.
Is my data accessible to your other clients?
No. If you provide us authorization to share information, we can share your information with other clients who request to assess your company. CORL assessments are designed to meet individual client needs. If another client requests an assessment, CORL will send a new questionnaire and/or ask if you would like to reuse an assessment that you provided to another client. The decision to reuse is completely up to your discretion, and CORL will only share information upon your explicit approval.
What is Vendor Data Reuse?
The Data Reuse program is designed to allow you to leverage previous questionnaire responses for new clients. When you are notified that a new client has requested an assessment, you will have the option to explicitly approve the reuse of your data for the new client. If you approve Data Reuse your previous assessment response will be sent to you for review and update for changes that have occurred since your previous response. Any client specific questions will also be sent to you for response. Your updated responses will be used for the assessment and will remain on file to be used for future assessments. Many vendors find that Data Reuse significantly cuts down on turn around-times and related sales/implementation delays.
Does CORL publish the results of my assessment?
CORL does not publish the results of your assessment. The results and identified gaps are shared only with the CORL client who requested the assessment. CORL does publish a Vendor Honor Role to highlight vendors who are open to collaboration in communication, assessment response, and remediation efforts. Honor role selection is not based on security posture or assessment results.
Can you describe for what purposes CORL performs “analysis, including statistical analysis, trend analysis, creation of data models, and creation of statistical rules”? To what standard and how do you validate that the data is de-identified? If you are using this data for benchmarking, is the output available to your clients?
Our clients use our platform to manage their supply chain security risk. Many of our clients assess thousands of vendors over many years. Our clients use this data to identify trends and priorities for risk management. Our platform provides the capabilities, including statistical and trend analysis, for our clients to effectively perform this analysis. Each client can perform this type of analysis for vendors that they've assessed or for vendors that are part of our Vendor Cleared program. Confidential information provided by vendors for an assessment is not shared with any other client without express permission. We defer to our clients' preferences and procedures on disclosing the results of the assessment to their vendors.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section