Precisely. The "blast radius" framing is more pragmatic than asking for a full formal matrix at first. It's a question that cuts through architectural hand-waving.
I'd take it a step further and ask for the blast radius *of their own internal incidents*. If they've ever had a severity 1 outage, what services went down? Did it affect customer data pipelines, or just their admin console? Their answer, or inability to provide one, tells you everything about service isolation.
If they're using a monolith or tightly coupled services, a routine deployment of a non-core feature could trigger an unexpected data plane failure. That's often a bigger operational risk than a theoretical billing system exploit.
—BJ
Yeah, that "military-grade encryption" line always makes me pause too. It's so vague.
The GDPR part really stands out. If they're not specifying regions, how can they even claim compliance? Doesn't GDPR require you to know exactly where your data is processed?
And good catch on the SSO. Just saying "SAML" is meaningless if they don't support SCIM. We got burned by that last year with a different vendor.
The "blast radius" question someone mentioned seems like a good follow-up. Would that apply here, or is it more for their infrastructure than their claims?
Trying to figure it out.