Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Security Basics for Custom Software Buyers
Custom Software

Security Basics for Custom Software Buyers

You do not need to be technical to ask the questions that matter. What to require, what to verify, and what a good answer sounds like.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Ask how authentication works, where data is stored, who can access production, how dependencies are kept patched and what happens in a breach. Vague answers on any of those are the signal, regardless of your own technical knowledge.

The short answer

Five questions cover most of it: how do users prove who they are, where does the data live, who can reach production, how do you know your dependencies are patched, and what happens if there is a breach. You do not need to evaluate the answers technically. You need them to be specific.

A supplier who answers all five clearly has thought about it. One who answers generally has not.

Authentication and access

  • How do users log in, and is multi-factor available for privileged accounts?
  • How are permissions structured, and can they be fine-grained enough for your needs?
  • What happens when someone leaves your organisation?
  • Is there an audit trail of who accessed what?
  • Are there any shared accounts, and if so, why?

Shared accounts are the answer to watch for. They are always convenient and they remove accountability entirely.

Where the data lives

QuestionWhy you care
Which country and region?Data residency obligations
Whose cloud account?Ownership if the relationship ends
Encrypted at rest and in transit?Baseline expectation
Who else can access it?Subprocessors you inherit
How are backups stored and tested?A backup never restored is a hope

The second row matters commercially as well as technically. Infrastructure in the supplier's account is a dependency that surfaces at the worst possible moment.

Keeping dependencies patched

Modern software is mostly other people's code, and vulnerabilities are found in it continuously. The question is whether anyone is watching.

A good answer describes automated scanning, a process for acting on findings, and who is responsible. A weak answer is that they use up-to-date libraries, which describes a moment rather than a process.

Breach response

  1. Who do they tell, and how quickly?
  2. What logging exists to work out what happened?
  3. Who is responsible for notifying your customers or a regulator?
  4. What does the contract say about liability?
  5. Has the process ever been tested?

Point two is the practical one. Without adequate logging, nobody can tell what was accessed, and the answer defaults to assuming the worst.

Proportionate, not maximal

A small internal tool does not need the controls of a payment system. Asking for everything drives cost without reducing meaningful risk.

Decide what would actually be damaging if it leaked, and spend accordingly. That conversation is more useful than a generic security checklist.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Do we need a penetration test?

For anything handling sensitive data or facing the internet with real consequences, it is worth it. For a small internal tool, proportionality applies.

Should infrastructure be in our cloud account?

Generally yes. It costs nothing extra and removes a dependency if the relationship ends.

What if we do not understand the answers?

Judge specificity rather than content. Vague answers are a signal on their own, and an independent reviewer is inexpensive.

Who is liable if there is a breach?

Whatever the contract says, and it is worth reading before signing. Take advice on anything handling personal data.

Keep reading

More on Custom Software

Custom Software

When Off-the-Shelf Software Stops Fitting

Every platform is bent to fit eventually. The signals that you have passed the point where configuration is cheaper than a custom build.

Custom Software

Turning a Critical Spreadsheet Into Software

Most businesses have one. Why it survived, what it encodes that nobody wrote down, and how to replace it without losing the knowledge inside it.

Start here

Weighing up a custom build?

Tell us what you are trying to fix and what you already run. We will give you an honest view on whether custom software is the right answer, what it would involve and a realistic range. If configuring what you have would do the job, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →