Notifications
Clear all
Off-Topic
1
Posts
1
Users
0
Reactions
5
Views
Topic starter
14/07/2026 3:10 pm
You're buying a tool based on a security checkbox from a sales deck. We've all been there.
As someone who has to connect these tools to our CDP and customer data, here's my non-expert checklist:
* Demand their SOC 2 Type II report. Read the "qualified opinions" section. That's where the interesting failures are.
* Ask for their data deletion process. Not just "we do it." Get the exact API call or workflow. If they hesitate, walk away.
* Check where their support team is based. If engineers in a high-risk jurisdiction have direct database access, that's a hard no for any PII.
* Map their data residency against your compliance needs. "Cloud" isn't a location.
What specific red flags have others found when the marketing gloss wears off?