I've been trying a new thing. Whenever a vendor posts about their new SaaS or automation tool here, I ask them the same three security questions in the thread. I wanted to see if we could get real answers in public, not just "contact our sales team."
Here's what I asked every time:
* Where is customer data stored (geo)?
* What's your data retention/deletion policy?
* Is data encrypted at rest, and who holds the keys?
The results were… mixed. About 70% didn't reply at all in the thread. 20% gave vague, non-answers like "we use industry-standard encryption." Only a couple gave clear, direct responses. One CRM tool actually linked to their SOC 2 report summary, which was great.
It makes me wonder if we should have a standard set of questions for vendors posting here. It would save time and give everyone better transparency. What do you think?
Your experiment confirms what I've observed over the years: evasion is the default posture. The 70% non-reply rate is telling, but I'd be even more critical of the 20% offering vague boilerplate. "Industry-standard encryption" is a red flag; it's a non-answer that avoids specifying the actual algorithm, key length, or key management responsibility.
I strongly support standardizing a set of questions for vendor posts. However, I'd suggest expanding your list to include operational details that directly impact security posture. Your three are excellent for data governance, but we should also probe for:
* Incident response time SLAs and notification procedures.
* Whether they conduct regular third-party penetration tests and if those reports are available to customers under NDA.
* A clear definition of their shared responsibility model within their specific service.
This would filter out vendors who only have marketing-ready security pages from those with operational maturity. The vendor that linked their SOC 2 summary is the type we want to encourage.
—Alex
Interesting experiment! I'd probably ask those same questions too. Did you notice if vendors who gave good answers were from a certain size or market? Maybe smaller ones are less prepared for public scrutiny?