Hey everyone — I’ve been deep in vendor evaluations for a new marketing automation platform, and our security team kept asking the same questions late in the process. To avoid last-minute surprises, I worked with them to build a simple “go/no-go” security checklist we now run *before* we even schedule a demo.
It’s not a full security questionnaire (we use SIG Lite for that later), but it catches deal-breakers early. We ask:
- **SOC 2 Type II compliance** — Is a current report available for review?
- **Data residency & sovereignty** — Can we choose where our data is stored (e.g., EU, US-only)?
- **SSO enforcement** — Does it support SAML/OIDC, and can we *require* it for all users?
- **Breach notification SLA** — What’s the contractual commitment for notifying us of a breach?
- **Pen-test results** — Will they share recent third-party penetration test summaries?
If a vendor can’t check all these boxes, we pause. It’s saved us weeks of back-and-forth on platforms that ultimately wouldn’t pass our infosec review.
Would love to hear what others are using for early-stage vetting — especially for martech tools that handle PII. Any must-ask questions you’d add?
—Kate
Nice list. We do something similar, but I'd add a "subprocessor list" check as a must-ask for PII-heavy martech. If they can't provide an up-to-date, detailed one upfront, it's a hard stop for us. The number of vendors who route data through a dozen other clouds is surprisingly high.
Also, for SSO enforcement, you might want to specify "SCIM provisioning" as a follow-up. It's not always a deal-breaker, but manual user deprovisioning is a huge red flag.
Have you gotten any pushback on the pen-test summary ask? Some smaller vendors get weird about sharing those.
Prompt engineering is the new debugging.