FAQ

The questions everyone asks

Auditors, spreadsheets, what we cannot watch, what it costs, and what happens if we vanish. Straight answers.

01Question

Does my auditor actually accept this?

Dormouse produces evidence that you monitored the sources you said you would, on the cadence you promised, with a record that cannot be quietly rewritten. That is what vendor-management controls ask for: evidence of ongoing monitoring. Auditors evaluate evidence, not logos, so the honest answer is to show yours the sample report and ask. The integrity section is designed for exactly that conversation, and the record can be verified on their machine, not ours.

02Question

Is this not just a spreadsheet I could keep myself?

You can perform the control manually, and our SOC 2 guide describes how. The difference is proof. A spreadsheet can be edited after the fact and says nothing about whether the looking happened on schedule. Dormouse's record is hash-chained, so a quiet month is as provable as a caught change, and a skipped window shows as a gap instead of disappearing.

03Question

What happens if you disappear?

You keep everything. The evidence lives in a single database file that exports with you, along with its integrity key and instructions for verifying the history independently. The export right is written into the service agreement. You are never locked in, and evidence you already paid for keeps working without us.

04Question

What can Dormouse not watch?

Pages that only render with JavaScript in a browser, pages behind logins, PDFs, and pages guarded by bot management that blocks non-browser fetchers. We tell you which of your vendors fall in those buckets during the baseline instead of pretending, and where possible we watch an equivalent fetchable source.

05Question

How fast will I hear about a change?

Every watched page is checked every 12 hours, so a change is detected within at most one cycle of appearing. Alerts arrive by email with the exact diff and a plain-English note, and every change also lands in the monthly report with the proof chain.

06Question

Do you need credentials to my vendors or my systems?

No. Dormouse watches public pages: subprocessor lists, DPA pages, trust centers. It holds no credentials of yours, no access to your systems, and no personal data beyond the contact details you give us for delivery.

07Question

What does it cost?

The founding rate is $199 a month or $1,990 a year, locked for life for the first ten teams, then the standard rate applies for new customers. Every engagement starts with a free baseline report on your real vendors, no card required, so you see the actual artifact before paying anything.

08Question

How is the record tamper-evident?

Every check is an entry in a keyed hash chain: each entry's hash covers its contents and the entry before it, so editing, inserting, or deleting history breaks the chain visibly. Reports carry the chain head so the trail can be re-verified against a value you hold outside our systems. The full mechanics, including the attacks we ran against it before launch, are public on the proof and audit pages.

09Anything else

Ask directly.

Email [email protected] and a human answers. The fastest way to evaluate the product remains the free baseline report on your real vendors.