Skip to main content

Guide

A 30-minute vendor security review using public evidence

The questions to answer before you email sales, in the order that saves the most time.

Last updated 17 Sep 2026

  1. Search the vendor on CertReports and open the security page. Note the registry-verified rows first; they need no NDA.
  2. Check the framework your policy requires. SOC 2 Type II or ISO 27001 with a scope that covers the product you are buying.
  3. If you will send PHI, check the HIPAA row for BAA availability and covered products.
  4. If you transfer EU or UK personal data, check the DPA, SCC and DPF facts on the GDPR page and the subprocessor list.
  5. Look at the change history. A lapsed certificate or a removed subprocessor is a question for the vendor, not a verdict.
  6. Compare against two same-category alternatives with evidence.
  7. Add the vendor to a watchlist so you hear when a state changes.
  8. Only then request the restricted-use report through the vendor trust centre.
Everything above is public. The report request is the last step, not the first.