Assessing Third-parties for Security Review
Last updated: September 16, 2025
When you want to add a new vendor or tool to your organization, you'll need to go through a security review process to ensure it meets your compliance requirements.
Required Information from the Vendor
To initiate a vendor security review, gather the following information from the vendor:
Description of services - What services they provide and what information they store or process
Architecture overview - High-level overview including cloud service providers used, encryption standards, and data flows
Security documentation - Copy of their information security policy and other available security collateral
Security assessments - Any vulnerability assessments or penetration testing they've completed (if available)
Third-party audits - Estimated completion dates for any planned audits like SOC 2
Review Process
Once you have the vendor's security information:
Submit the vendor details and security questionnaire responses to your security team
The security team will evaluate the vendor's security posture and compliance status
For vendors without completed audits (like SOC 2), the team may be more cautious but will assess based on your organization's risk tolerance
You may be approved to trial the tool while relying on existing security controls (such as GitHub's security controls for code review tools)
Trial vs. Full Implementation
If you're not ready to fully commit to a vendor but want to trial their services, you can often proceed with testing while the security review is ongoing. Make sure to:
Clarify the scope of what you'll be reviewing or testing
Understand what security controls are in place during the trial period
Confirm any limitations on data access or processing during the trial
Your security team will provide guidance on whether you can proceed with trialing based on the vendor's current security posture and your organization's risk tolerance.