The SaaS Security Checklist: What to Verify Before Signing Up

Security is the hidden contract term you don't read until it's too late. Here's what to verify before you sign.

By The StackMatch Research Team

74% of SMBs don't review vendor security before signing

74%Skip security review before signing
$150KAverage breach cost for SMB
60%of SMBs close within 6 months of a breach

Based on vendor security assessment data from 500+ SMBs.

Security by default isn't enough

Every vendor says they take security seriously. But 'secure' means different things to different companies. A vendor that stores payment data in plain text thinks they're secure because they have a password policy. Here's the minimum you should verify before any vendor gets access to your business data.

Encryption, access controls, and a signed DPA are the baseline — not the finish line — of vendor security.

Encryption standards

Verify encryption in transit (TLS 1.2+ is table stakes) and at rest (AES-256 for stored data). Ask about key management — is your data encrypted with your own key (customer-managed encryption keys) or a shared key? CMEK means even the vendor can't read your data without your key.

86%
of SaaS vendors use AES-256 for data at rest

Vendor security evaluation checklist

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • SOC 2 Type II report (annual audit)
  • GDPR compliance (if handling EU data)
  • HIPAA compliance (if handling health data)
  • SSO/SAML support for access control
  • MFA required for admin accounts
  • Audit log of all access and changes
  • Data retention and deletion policy
  • Incident response plan with SLA
  • Penetration test results (last 12 months)
  • Bug bounty program (shows security culture)
  • Vendor security questionnaire response
  • Subprocessor list (who else touches your data)
  • Data center location and redundancy

Compliance certifications

Never accept 'SOC 2 in progress.' A real SOC 2 Type II report covers 6+ months of audited controls. If a vendor claims compliance, ask for the actual report (with financial details redacted). Vendors that won't share their SOC 2 report likely don't have one.

Compliance certs by vendor size

The question that reveals security culture: 'When was your last penetration test?' A vendor that runs pen tests quarterly and shares the executive summary is security-conscious. A vendor that can't remember their last pen test is storing your data on hope.

Access controls

Ensure the vendor supports role-based access control (RBAC), single sign-on (SSO with SAML/OIDC), and mandatory MFA for admin accounts. If a vendor offers 'admin' vs. 'user' as the only two roles, your security is only as strong as your weakest admin password.

Run the free StackMatch audit to see security ratings for your current vendors and identify which ones need a security review before your next renewal.

Run your own audit
More from the blog