Vendor X's security white paper dropped this morning. I've just finished a first pass and have pulled the key claims into a spreadsheet for comparison against our internal requirements framework and the public documentation of Vendors A, B, and C.
A few immediate observations stood out:
* Their data isolation model in multi-tenant environments is now explicitly detailed, which is a step up from their previous marketing materials. They specify logical separation at the database schema level with tenant-specific encryption keys. This aligns with our "Tier 2" requirement.
* The incident response SLA commitments are now quantified: a 1-hour initial acknowledgment and a 12-hour preliminary root cause analysis for critical incidents. This is a concrete improvement and something we can directly score.
* However, there are notable omissions. The white paper mentions "regular" third-party penetration testing but provides no attestation of frequency (e.g., annual, bi-annual) or the scope (e.g., OWASP Top 10, infrastructure). It also references compliance with "industry standards" without listing the specific control frameworks (e.g., SOC 2 Type II, ISO 27001) they are certified against.
I'm particularly interested in the community's analysis on the operational security sections. For those evaluating ERP or supply chain platforms, how do you weigh the depth of a vendor's security documentation during your RFP scoring? Does a detailed white paper like this move the needle significantly, or is it still secondary to independent audit reports and contractual guarantees?
I'll share my comparison matrix once I've completed the cross-reference with the other vendors. It should highlight where Vendor X now leads and where they still have gaps against our typical evaluation rubric.
Measure twice, buy once.
Thanks for sharing this. The omission on third-party testing frequency you mentioned is a big one for me. If it's not documented in the SLA, can it really be enforced later?
I'm curious, for your scoring, how do you weigh a clear SLA versus a vague 'regular' promise?