Before a new software or technology vendor touches your systems or your data, ask for proof of how they protect it. A vendor security assessment doesn’t have to be complicated. Find out what security practices or certifications they can show you, where your data will be stored, which other companies touch it, and what happens to their access when the contract ends. Then put those expectations in the agreement itself. Skip that step and a weak vendor becomes your problem: their mistake can reach your systems, your customers’ information, and the money and hours you spend cleaning it up.

This is ordinary due diligence. You’d check references before hiring a contractor and read the terms before signing a lease. Same habit, pointed at security.

What should you ask a vendor about security before you sign?

Ask how they protect the data you’ll hand over, and ask for evidence rather than assurances. That means current security certifications or a written summary of their controls, the location and handling of your data, the names of any other companies involved, and their process for notifying you if something goes wrong.

You’re not inventing these questions from scratch. CISA, the Cybersecurity and Infrastructure Security Agency, publishes vendor and supplier assessment guidance for small and midsize businesses built around a standard set of questions to work through when buying technology hardware, software or services. It covers outsourced IT providers and cloud-hosted tools, and one of its questions is whether the vendor has contractual obligations to protect the information and systems it handles. Worth noting where that obligation lives: in the contract.

A good vendor answers these without friction. A vendor that stalls, redirects you to a marketing page, or treats the questions as an insult has told you something useful too.

Where your data lives and who else touches it

Ask where your data is stored and whether it ever leaves that environment. Then ask the question owners skip: who else gets to see it. A vendor may run parts of its service through other companies, like a hosting provider or an analytics service. Those companies are sometimes called subprocessors, and the practical meaning is plain enough. Your data can end up in the hands of a business you never evaluated and never signed anything with.

You don’t need a full inventory of every downstream party. You do need to know whether the vendor keeps one, whether it will tell you when that list changes, and whether it passes your security requirements down the chain. If nobody at the vendor can answer that, nobody there owns it.

What happens to access and data when the contract ends

Ending a vendor relationship is easier to negotiate before it starts. Settle it now: how your data gets returned or deleted, in what format, and on what evidence. Settle the credentials too. Integrations, admin accounts and API keys keep working long after the invoices stop, and a login nobody remembers is still a working door into your business.

Getting the terms right up front doesn’t finish the job. Someone still has to close those accounts when the day comes, which is why it helps to audit vendor access after the contract ends as a separate, deliberate step.

Why does the contract matter more than the sales conversation?

Because a sales conversation isn’t enforceable and a contract is. Whatever a vendor tells you about encryption or breach notification only binds them once it’s written into the agreement you both sign. The contract is also the place where you reserve the right to revisit the arrangement later, while you still have leverage.

Some businesses are legally required to work this way. The FTC’s Safeguards Rule applies to companies whose activities are financial in nature — tax preparers, lenders, collection agencies and financial advisors, for example. Covered businesses must select service providers capable of maintaining appropriate safeguards, spell out security expectations in the contract, and build in monitoring plus periodic reassessment of whether that provider is still right for the job. A service provider, in this context, just means an outside company handling customer information on your behalf.

Two things follow. Even when an outside company runs part of your security program, the responsibility stays with you. And if you’re unsure whether the rule reaches your business at all, that’s its own question — we’ve written separately on whether the FTC Safeguards Rule applies to your business. If it doesn’t cover you, the legal obligation isn’t yours. The practice is still sound.

What belongs in writing

A short, specific set of terms does more than a long one nobody reads:

  • Security expectations stated plainly, not implied by a marketing page.
  • Notification terms if the vendor has an incident touching your data.
  • Whether your data can be shared with other companies, and on what conditions.
  • Your right to review or reassess the vendor’s security during the term.
  • What happens to your data and their access when the agreement ends.

Which vendors deserve the closest look?

Scale the review to the access. A vendor that connects to your core systems, handles customer or financial records, or integrates deeply enough to read and write data across your business earns a hard look. A tool that sits off to the side and never sees sensitive information needs far less.

Sort candidates by what you’re actually handing over. Broad system access sits at the top: anything with administrative rights, anything that syncs with the systems your operation runs on. Financial and customer data sits alongside it. So does a deep integration, because the connection itself becomes a path between the vendor and everything it touches. Further down are the narrow tools with a single job and no meaningful data. They still deserve a question or two. They don’t deserve the same scrutiny as a system of record.

O&O Systems offers a free security risk assessment that scans your own domain for risky email settings, leaked passwords, open services, and SSL issues, giving you a clear snapshot of your own exposure before you extend that kind of access to a new vendor.

Renewals count as decision points too. Access that was narrow at signing can widen as a vendor adds features and your team adds integrations. The renewal is when you can still say no.

Frequently Asked Questions About Vendor Security

What if a vendor won’t share any security documentation?

Treat the refusal as an answer. Some vendors limit detailed reports to signed non-disclosure agreements, which is reasonable and easy to arrange. A flat refusal to describe their controls in any form is different. If they won’t put their security in writing before the sale, expect less cooperation after it.

Is a certification enough on its own?

It’s evidence, not a verdict. A certification tells you an outside party reviewed something against a standard. Check what was in scope, whether the product you’re buying was covered, and whether the report is current. A certificate covering one part of a vendor’s operation says little about the rest.

Does a small, low-access tool need the same review?

No. Match the effort to the exposure. A tool with no sensitive data and no system connection can pass with a few basic questions about data handling and account control. The moment it asks for a login to another system, or for customer records, it moves into the higher tier.

Who should run the vendor security review inside a small business?

Someone has to own it by name, or it falls between the buyer and the IT side. In a smaller organization, that can be the operations leader who controls the purchase, working with whoever supports your technology. The owner doesn’t need to be technical. They need the authority to delay a signature.

Should a renewal get the same scrutiny as a new vendor?

A renewal deserves a real look, though not always a full one. Ask what’s changed: new features, new integrations, new data flowing in, new companies in the chain behind them. If the answer is nothing and the original terms still hold, a short confirmation is fair. If the footprint grew, review it like a new purchase.

Talk Through a Vendor Review Before You Sign

If a vendor is on your desk right now and you’re not sure what to require of them, you can contact O&O Systems about a vendor security review. Bring the proposal, the access the vendor is asking for, and the questions you’d rather have answered before the signature than after.