Everyone tells you to trust a security platform with your compliance. But who audits the auditor?
Start with the basics. They should be an open book. Ask for:
- Their SOC 2 Type II report (not just Type I). Read the auditor's opinion and the exceptions.
- Penetration test results from a reputable third party. Not a glorified vulnerability scan.
- Their own subprocessor list and how they manage those vendors.
If they hesitate on any of that, walk away. Seen too many "security" companies with softer internal controls than the clients they're certifying.
Also, check where your data actually lives. Their infrastructure provider (AWS, GCP) is only as good as *their* configuration. Ask about their cloud security posture management. It’s 2024. "We use AWS" is not a security policy.
CRM is a means, not an end.