Think Build Implement Repeat
SaaS & Product

Vendor Security Questions Worth Asking, and the Answers to Expect

Last updated:

Proportionate diligence

Enterprise vendor assessments run to hundreds of questions and are not appropriate for a business buying a £200-a-month tool. But asking nothing is how you end up dependent on a supplier who cannot answer basic questions.

Five questions is proportionate. Ask them in writing, and keep the answers.

1. Where is our data stored and processed?

Country and provider. This matters for data protection, and it is the question that reveals whether the supplier has thought about it.

A vague answer here — “in the cloud” — is itself informative about how much attention they have paid.

2. Who at your company can access it?

Some support access is normal and necessary. What you want to hear is that access is limited, logged and requires a reason, rather than that everyone in the company can read customer databases.

A good answer sounds like: “support engineers can access customer data with a ticket reference, it is logged, and access is reviewed quarterly.” A concerning answer is a reassurance without a mechanism.

3. What happens if you go out of business?

For anything business-critical, this deserves an answer. Options include escrow, an export you hold yourself, or simply a documented process for getting your data out quickly.

The practical protection for most small businesses is a regular export you keep, which also covers the less dramatic scenario of wanting to leave.

4. How do we get our data out?

  • Full export, including attachments and history, not just the main tables
  • In a usable format, not a proprietary one
  • Available on demand rather than by request with a delay
  • At no additional charge, ideally — exit fees are a warning sign

5. Have you had a security incident?

The answer “no, never” from an established supplier is less reassuring than a candid account of something that happened and what changed afterwards.

What you are assessing is whether they would tell you. A supplier who discusses a past incident openly is more likely to tell you about the next one promptly.

What to do with the answers

File them. If a supplier will not answer in writing, weigh that. And revisit for critical suppliers annually — companies get acquired, infrastructure moves, and policies change without customers being told.

Frequently asked questions

Do we need a signed data processing agreement?

Where the supplier processes personal data on your behalf, yes, and most reputable vendors provide one as standard. Its absence is worth asking about.

What about certifications like ISO 27001?

They indicate a documented approach and are not a guarantee. For smaller suppliers, sensible answers to the five questions matter more than a certificate.

How often should we review suppliers?

Annually for anything critical, and whenever a supplier is acquired or changes its terms materially.

What if a critical supplier answers badly?

Weigh the risk against the switching cost, mitigate what you can — your own exports, restricted data — and factor it into your next renewal decision.

Keep reading

Buying software that will hold your customer data?

Send those five questions before you sign. We are happy to be asked them too.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

SaaS DevelopmentCustom Software Development