What to ask the vendor directly

10 min

Public evidence gets you to a shortlist. These questions get you the rest, and how a vendor answers them is itself the answer.

The five that matter

  1. "Describe your last security incident and what changed afterwards." Every vendor of any size has had one. A vendor who claims none has either not been looking or is not telling you. What you are testing is whether the answer contains a specific change.
  2. "Who can access my data, from where, and how is that logged?" Ask for the support access model in writing. "Our engineers can access customer tenants for troubleshooting" is fine and normal; discovering it after signature is not.
  3. "What happens to my data when I leave?" Export format, retention period, deletion confirmation. Ask before you are emotionally invested.
  4. "Show me your advisory page and your last three advisories." You are reading for clarity and speed, not for count.
  5. "Which of your components are third-party, and how do you track their vulnerabilities?" An agent running with privilege on every endpoint you own is a supply chain question, whether or not the vendor treats it as one.

Reading the answer

The content of the answer matters less than its shape. Specific, dated, slightly uncomfortable answers are good signs. Answers that redirect to a compliance certification are not answers — an audit report says a control existed on the day it was tested, which is a different claim from the one you asked about.

Sign in to track progress