Classification: NDA-scoped reviewer documentation
Vendor Security Questionnaire Template
Use this template to send your required questions for review.
Company name: Primary contact: Security contact: Required due date:
1) Company and security program overview
- Describe your security ownership model and who is responsible for security decisions.
- Describe your incident response process at a high level.
- Describe your vulnerability management process.
2) Data handling
- What customer data categories do you process?
- Where is customer data stored and processed?
- How is data encrypted in transit and at rest?
- What is your retention approach for customer data and operational logs?
- How can customers request deletion and data access?
3) Access controls
- How is employee/admin access controlled?
- How do you enforce least privilege?
- How do you revoke access on role change or offboarding?
4) Infrastructure and operations
- Describe your hosting model and deployment control approach.
- Describe backup and recovery practices.
- Describe business continuity/disaster recovery approach.
5) Incident and disclosure
- How are customers notified of material incidents?
- What is your responsible disclosure process?
6) Third-party risk
- List subprocessor categories and purpose.
- Describe how subprocessor changes are managed.
7) Requested artifacts
- Trust Center links
- Completed questionnaire response file
- Additional NDA-gated artifacts
8) NDA and scope
NDA required? (yes/no) Requested restricted scope: