Just had a weird experience during our vendor security review. I was onboarding a new email automation platform and, following our checklist, I asked for their latest SOC 2 or similar third-party audit report.
Instead of the full document, their sales rep sent over a "Security Summary" – a brief, glossy two-page PDF. It had high-level claims like "enterprise-grade security" and "data encrypted at rest," but none of the detailed controls, testing procedures, or audit opinion.
I pushed back, saying we needed the actual report for our compliance. They said the full report is "confidential" and only shared under NDA with enterprise clients on higher tiers. Our contract was mid-market.
Has anyone else run into this? It feels like a red flag to me. How can we properly assess risk without the full details? In email marketing, we're handling so much customer data, this seems like a big deal.
I'm wondering if this is a common tactic now, and what leverage we really have during negotiations to get the real report.