Skip to content
Notifications
Clear all

Just built a 'go/no-go' checklist based on our security team's input.

2 Posts
2 Users
0 Reactions
1 Views
(@katem)
Trusted Member
Joined: 1 week ago
Posts: 44
Topic starter   [#5552]

Hey everyone — I’ve been deep in vendor evaluations for a new marketing automation platform, and our security team kept asking the same questions late in the process. To avoid last-minute surprises, I worked with them to build a simple “go/no-go” security checklist we now run *before* we even schedule a demo.

It’s not a full security questionnaire (we use SIG Lite for that later), but it catches deal-breakers early. We ask:

- **SOC 2 Type II compliance** — Is a current report available for review?
- **Data residency & sovereignty** — Can we choose where our data is stored (e.g., EU, US-only)?
- **SSO enforcement** — Does it support SAML/OIDC, and can we *require* it for all users?
- **Breach notification SLA** — What’s the contractual commitment for notifying us of a breach?
- **Pen-test results** — Will they share recent third-party penetration test summaries?

If a vendor can’t check all these boxes, we pause. It’s saved us weeks of back-and-forth on platforms that ultimately wouldn’t pass our infosec review.

Would love to hear what others are using for early-stage vetting — especially for martech tools that handle PII. Any must-ask questions you’d add?

—Kate



   
Quote
(@llm_experimenter)
Estimable Member
Joined: 2 months ago
Posts: 55
 

Nice list. We do something similar, but I'd add a "subprocessor list" check as a must-ask for PII-heavy martech. If they can't provide an up-to-date, detailed one upfront, it's a hard stop for us. The number of vendors who route data through a dozen other clouds is surprisingly high.

Also, for SSO enforcement, you might want to specify "SCIM provisioning" as a follow-up. It's not always a deal-breaker, but manual user deprovisioning is a huge red flag.

Have you gotten any pushback on the pen-test summary ask? Some smaller vendors get weird about sharing those.


Prompt engineering is the new debugging.


   
ReplyQuote