Security architecture
How access is granted, reviewed, and revoked; how secrets are held; how environments are separated; how changes reach production; and what the threat model actually covers.
Working structure
Procurement review is where products discover which of their assumptions were never written down. The questions are rarely surprising; the problem is that answering them takes weeks because nobody owns the answers.
This checklist sets out the questions enterprise buyers ask, and what separates a credible answer from a deferral.
Build your brief01 / WHAT BUYERS ASK
The specific wording varies by buyer. The underlying questions rarely do.
How access is granted, reviewed, and revoked; how secrets are held; how environments are separated; how changes reach production; and what the threat model actually covers.
What data is processed and why, where it resides, how long it is retained, who the subprocessors are, and how deletion and export requests are honoured in practice.
Which standard is claimed, at which conformance level, for which parts of the product, and what evidence supports the claim. An untested claim is a liability rather than an asset.
Availability expectations, support hours and escalation, incident notification timelines, monitoring, and demonstrated recovery rather than a documented intention.
Which certifications exist, their exact scope, who issued them, and what falls outside. Overstated scope is discovered during review and it is expensive.
Liability, data processing terms, subprocessor change notification, exit and data portability, and what happens to the product if the supplier relationship ends.
02 / WHAT A GOOD ANSWER LOOKS LIKE
Sample working structure
The Markdown file carries the question set and prompts described above. It is a preparation aid and is not legal advice or an assurance opinion.
03 / QUESTIONS
Security architecture and access control, data protection and residency, subprocessor disclosure, accessibility conformance, availability and support commitments, incident and disclosure process, business continuity, and evidence of the controls claimed.
Unowned answers. A question that no named person is accountable for tends to circulate until someone guesses, and a guess that later proves wrong is more damaging than an honest gap with a remediation date.
Admit the gap, with an owner and a date. Enterprise buyers routinely accept known gaps on a credible plan. They rarely forgive an answer that turns out to be untrue.
Before the first enterprise opportunity, not during it. Most of the answers are architectural, and architecture cannot be changed on a procurement timeline.
Next decision
The answers are architectural, so they are cheapest to establish early.