What to Ask a Software Partner About Data Security (Before You Sign)
A due-diligence checklist for evaluating how seriously a development partner treats your data — from encryption to incident response.

Security is a process, not a certificate
Certificates and badges are useful signals, but day-to-day practices protect your data: how access is granted, how code is reviewed, how secrets are stored, and what happens when something goes wrong. Ask about the process behind the badge.
The questions that reveal maturity
Who can access our data, and how is that access revoked? Is data encrypted at rest and in transit by default? How are secrets managed? Is there a documented incident-response plan with notification timelines? Vague answers to any of these are a red flag.
Contracts that protect you
Insist on a data-processing agreement naming purposes, retention periods, and sub-processors. Confidentiality clauses should survive contract termination, and deletion on exit should be verifiable — not just promised.
Privacy in the AI era
If your partner uses AI tooling, ask whether your data can end up in third-party training sets, how PII is handled before model calls, and what guardrails validate outputs. Responsible partners will have crisp answers because they have already done the work.


