- Search the vendor on CertReports and open the security page. Note the registry-verified rows first; they need no NDA.
- Check the framework your policy requires. SOC 2 Type II or ISO 27001 with a scope that covers the product you are buying.
- If you will send PHI, check the HIPAA row for BAA availability and covered products.
- If you transfer EU or UK personal data, check the DPA, SCC and DPF facts on the GDPR page and the subprocessor list.
- Look at the change history. A lapsed certificate or a removed subprocessor is a question for the vendor, not a verdict.
- Compare against two same-category alternatives with evidence.
- Add the vendor to a watchlist so you hear when a state changes.
- Only then request the restricted-use report through the vendor trust centre.
Everything above is public. The report request is the last step, not the first.