The SaaS Security Checklist: What to Verify Before Signing Up
Security is the hidden contract term you don't read until it's too late. Here's what to verify before you sign.
74% of SMBs don't review vendor security before signing
Based on vendor security assessment data from 500+ SMBs.
Security by default isn't enough
Every vendor says they take security seriously. But 'secure' means different things to different companies. A vendor that stores payment data in plain text thinks they're secure because they have a password policy. Here's the minimum you should verify before any vendor gets access to your business data.
Encryption, access controls, and a signed DPA are the baseline — not the finish line — of vendor security.
Encryption standards
Verify encryption in transit (TLS 1.2+ is table stakes) and at rest (AES-256 for stored data). Ask about key management — is your data encrypted with your own key (customer-managed encryption keys) or a shared key? CMEK means even the vendor can't read your data without your key.
Vendor security evaluation checklist
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest
- SOC 2 Type II report (annual audit)
- GDPR compliance (if handling EU data)
- HIPAA compliance (if handling health data)
- SSO/SAML support for access control
- MFA required for admin accounts
- Audit log of all access and changes
- Data retention and deletion policy
- Incident response plan with SLA
- Penetration test results (last 12 months)
- Bug bounty program (shows security culture)
- Vendor security questionnaire response
- Subprocessor list (who else touches your data)
- Data center location and redundancy
Compliance certifications
Never accept 'SOC 2 in progress.' A real SOC 2 Type II report covers 6+ months of audited controls. If a vendor claims compliance, ask for the actual report (with financial details redacted). Vendors that won't share their SOC 2 report likely don't have one.
Compliance certs by vendor size
The question that reveals security culture: 'When was your last penetration test?' A vendor that runs pen tests quarterly and shares the executive summary is security-conscious. A vendor that can't remember their last pen test is storing your data on hope.
Access controls
Ensure the vendor supports role-based access control (RBAC), single sign-on (SSO with SAML/OIDC), and mandatory MFA for admin accounts. If a vendor offers 'admin' vs. 'user' as the only two roles, your security is only as strong as your weakest admin password.
Run the free BusinessAdvisor.Guide audit to see security ratings for your current vendors and identify which ones need a security review before your next renewal.
- Vendor Risk Assessment: The 50-Point Checklist Before You Sign
- Evaluating Vendor Support Quality Before You Sign
- Software Vendor Risk Assessment: The Questions You Should Ask Before Signing
- Why You Should Audit Your Software Permissions Quarterly
- SOC 2 Compliance: What Software Buyers Need to Know
- Software Audit Checklist: 20 Questions Before Your Next SaaS Renewal
