A vendor of ours once sent a breach notification that started with "one of our sub-processors experienced an incident" and ended with "your data may have been affected."
We were a team of nine. The first question was not what happened to them. The first question was what did they actually have of ours — and nobody in the room could answer it. Not the data inventory, not the notification deadline we'd agreed to, not even which sub-processors sat behind their product. We had signed the tool in an afternoon because the demo was good and the pricing page said security twice.
We spent that breach notification doing archaeology on our own procurement. Never again. Here's the checklist we use now — 12 questions, asked between verbal-yes and signature, when we still have leverage.
The 12 questions, in the order to ask them
- What exact data will you hold, and where? Field-level: emails, addresses, payment tokens, credentials, health fields. Region, cloud provider, whether backups leave it.
- Any breach or material incident in the last 24 months? The right answer isn't "no" — it's an honest account. Vendors who say never to everything are either lucky or not looking. The second is worse.
- Do you enforce MFA for staff accessing customer data — and for our admin account? Theirs matters. Ours we can verify today.
- How do we authenticate to your product? SSO, API key scoping, session timeouts — and how does a long-lived key get rotated when it leaks?
- Who are your sub-processors, and how are we notified when they change? The SaaS is never the whole chain. A published, versioned list with change notification is the mature answer.
- What's your breach notification commitment — in the contract, in hours? "Without undue delay" is a vibe. "72 hours from confirmation, to named contacts" is a term.
- Encryption at rest and in transit? Standard now. The differentiator is key management and what happens to your data on cancellation.
- SOC 2 / ISO 27001 — or a substitute? A full report under NDA beats a homepage badge. No report doesn't disqualify low-risk tooling; it should move them down a tier, not up.
- How is our data deleted on exit? Timeline, certificate of deletion, backups included.
- What can support see, and is it logged? "Break-glass access, logged, with a named approver" is the adult answer. "Support can log in as any customer" is a finding, not a feature.
- Pen tests — when, and will you share results under NDA? Annual external plus fixes-verified.
- Who is legally responsible if their breach becomes our notification event? Indemnification, liability cap, whether the cap covers regulatory fines. This one's for whoever signs.
The red-flag answers
- "Security info available on request" — then nothing arrives. If it's ignored before signature, it'll be ignored during an incident.
- "Never had any incidents and we don't do testing." No incidents and no testing means no detection. That's an unread history, not a clean one.
- "MFA is on enterprise plans." That's a pricing decision wearing a security costume.
- "We'll comply with applicable law." Law that binds them may not match your obligations to your customers.
- "We use industry-standard providers." That's a shrug with extra words. Ask for the list.
Tier it, or you'll never do it
The full questionnaire is for the tools that hold PII, credentials, payment data, or production access: payroll, CRM, identity, cloud, backups. Internal-only tooling gets five questions on the same call as pricing. Everything else gets registered and moves on — because the vendor list is the real deliverable. When the next breach notice lands, the 2am question is "which of our vendors just had a breach, and what did they hold?" A tiered spreadsheet answers that in ten minutes. Memory doesn't.
The insight that made the whole thing stick: you're not auditing their security — you're collecting the facts your own incident will need. Somebody else's breach notification is either a Monday-morning panic or a ten-minute lookup, and you decide which one at signature time.
We packaged this as part of the HIVE80lab ops kit — incident-response material built for small teams, not enterprise compliance theater:
- 🆓 The First 30 Minutes — free one-page incident quick-start checklist
- 📦 Ops Starter Kit — $14, incident response for small teams
- ⚙️ Automation Starter Pack — $19, pick-first workflows
Launch week: 30% off any paid kit with code HIVE-LAUNCH30 at checkout.
The full page (with the red-flag answers and the tiering table) lives on our ops-notes site: Vendor Security Review Checklist for Small Teams
Top comments (0)