Assessing Third-parties for Security Review

Last updated: September 16, 2025

When you want to add a new vendor or tool to your organization, you'll need to go through a security review process to ensure it meets your compliance requirements.

Required Information from the Vendor

To initiate a vendor security review, gather the following information from the vendor:

  1. Description of services - What services they provide and what information they store or process

  2. Architecture overview - High-level overview including cloud service providers used, encryption standards, and data flows

  3. Security documentation - Copy of their information security policy and other available security collateral

  4. Security assessments - Any vulnerability assessments or penetration testing they've completed (if available)

  5. Third-party audits - Estimated completion dates for any planned audits like SOC 2

Review Process

Once you have the vendor's security information:

  1. Submit the vendor details and security questionnaire responses to your security team

  2. The security team will evaluate the vendor's security posture and compliance status

  3. For vendors without completed audits (like SOC 2), the team may be more cautious but will assess based on your organization's risk tolerance

  4. You may be approved to trial the tool while relying on existing security controls (such as GitHub's security controls for code review tools)

Trial vs. Full Implementation

If you're not ready to fully commit to a vendor but want to trial their services, you can often proceed with testing while the security review is ongoing. Make sure to:

  • Clarify the scope of what you'll be reviewing or testing

  • Understand what security controls are in place during the trial period

  • Confirm any limitations on data access or processing during the trial

Your security team will provide guidance on whether you can proceed with trialing based on the vendor's current security posture and your organization's risk tolerance.