Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Vendor Security Questions Worth Asking, and the Answers to Expect
SaaS & Product

Vendor Security Questions Worth Asking, and the Answers to Expect

A short due diligence list for buying business software, proportionate to a small business rather than an enterprise.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Ask where data is stored, who can access it, what happens if they fail, how you get your data out, and whether they have had an incident. Five questions, proportionate for a small business, and the way they are answered tells you as much as the answers.

Proportionate diligence

Enterprise vendor assessments run to hundreds of questions and are not appropriate for a business buying a £200-a-month tool. But asking nothing is how you end up dependent on a supplier who cannot answer basic questions.

Five questions is proportionate. Ask them in writing, and keep the answers.

1. Where is our data stored and processed?

Country and provider. This matters for data protection, and it is the question that reveals whether the supplier has thought about it.

A vague answer here — “in the cloud” — is itself informative about how much attention they have paid.

2. Who at your company can access it?

Some support access is normal and necessary. What you want to hear is that access is limited, logged and requires a reason, rather than that everyone in the company can read customer databases.

A good answer sounds like: “support engineers can access customer data with a ticket reference, it is logged, and access is reviewed quarterly.” A concerning answer is a reassurance without a mechanism.

3. What happens if you go out of business?

For anything business-critical, this deserves an answer. Options include escrow, an export you hold yourself, or simply a documented process for getting your data out quickly.

The practical protection for most small businesses is a regular export you keep, which also covers the less dramatic scenario of wanting to leave.

4. How do we get our data out?

  • Full export, including attachments and history, not just the main tables
  • In a usable format, not a proprietary one
  • Available on demand rather than by request with a delay
  • At no additional charge, ideally — exit fees are a warning sign

5. Have you had a security incident?

The answer “no, never” from an established supplier is less reassuring than a candid account of something that happened and what changed afterwards.

What you are assessing is whether they would tell you. A supplier who discusses a past incident openly is more likely to tell you about the next one promptly.

What to do with the answers

File them. If a supplier will not answer in writing, weigh that. And revisit for critical suppliers annually — companies get acquired, infrastructure moves, and policies change without customers being told.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Do we need a signed data processing agreement?

Where the supplier processes personal data on your behalf, yes, and most reputable vendors provide one as standard. Its absence is worth asking about.

What about certifications like ISO 27001?

They indicate a documented approach and are not a guarantee. For smaller suppliers, sensible answers to the five questions matter more than a certificate.

How often should we review suppliers?

Annually for anything critical, and whenever a supplier is acquired or changes its terms materially.

What if a critical supplier answers badly?

Weigh the risk against the switching cost, mitigate what you can — your own exports, restricted data — and factor it into your next renewal decision.

Keep reading

More on SaaS & Product

Start here

Buying software that will hold your customer data?

Send those five questions before you sign. We are happy to be asked them too.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →