For companies buying software
Verify a tool before you hand it your data
A vendor questionnaire tells you what the vendor wants to say. We verify what can be confirmed and state plainly what cannot be confirmed at all.
01
Risk depends on what you use it for
The same vendor can be fine for one use case and unacceptable for another. That is why we start from context, not from the company name.
A social post scheduling tool
It gets content that will be public anyway and access to one social media account. Even with weak security, the damage is limited and reversible.
The same tool used for HR
It gets employee data, including bank account numbers and medical certificates. Same level of security, very different impact. Same technical assessment, different decision.
02
What we check on the vendor side
01
What the documents say
The contract, the data processing agreement, the subprocessor list and the terms. We look for clauses on model training, retention, deletion, transfers and unilateral changes.
02
Whether the documents agree
The terms and the privacy policy can say different things. A contradiction between documents is a finding in itself.
03
What is visible from outside
Certificates, headers, exposed endpoints, security documentation, a vulnerability disclosure channel, incident history.
04
What the vendor requests at integration
Which permissions it asks for, what it reaches and whether that is more than your use case needs.
05
What is missing
A missing published DPA or subprocessor list is a fact, not a gap in our knowledge. We record it as missing.
06
What to ask
Specific questions for the vendor where public information is not enough to decide.
03
What you get at the end
- A decision: accept, conditional, reject or unknown.
- The three most important reasons for that outcome.
- A list of what could not be confirmed and what it would take to close it.
- Ready-made questions for the vendor, if you want to dig further.
- Proposed contract conditions, if the decision is conditional.
- The date after which the result is no longer valid.
04
What this report does not replace
A legal opinion
We point out what a contract clause means for your use case and propose conditions. It is not legal advice and we don't pretend it is.
A test of the vendor's system
We don't test someone else's system without its owner's authorization. If the vendor grants it, that is a separate scope and a separate conversation.
Better to ask before you sign than after an incident
Describe the tool and what you want to use it for. We will reply with what can be established and how long it will take.