Identity and access
Confirm how users authenticate, reset access, and recover accounts.
Check whether role-based access controls are granular enough for your org structure.
Ask how the system logs privileged actions and access changes.
Data handling
Review what data is stored, where it is stored, and how long it is retained.
Check whether you can export records in usable formats without vendor help.
Ask how backups, deletion requests, and legal holds are handled.
Vendor controls
Request a plain explanation of incident response, vulnerability management, and patching practices.
Check whether sub-processors or third-party services are involved in hosting, analytics, or support.
Confirm whether security reports or audit summaries are available on request.
Next steps
Map the data you will collect and who can access it.
Review the retention and deletion policy before launch.
Decide how you will exit the platform if needed later.
- Confirm authentication and role controls.
- Verify retention, deletion, and export options.
- Review incident response and third-party dependencies.