Every tool you sign up for and every supplier you share data with becomes part of your security, whether you vetted them or not. When a vendor is breached, your customers' information can be exposed even though you did nothing wrong, and "our supplier lost it" is not a defence your clients or a regulator will accept. You do not need an enterprise procurement process to check a vendor, just a short, consistent set of questions and the sense to notice a red flag.
Right-size the check to the risk
Not every vendor needs the same scrutiny. The test is simple: how much of your data, and how sensitive, does this vendor touch? A tool that stores your customer list or processes payments deserves real questions; a font library does not. Spend your attention where a breach would actually hurt, which for most small businesses means anything holding personal, financial, or client-confidential information.
The questions that matter
- Do you have recognised security certification? A SOC 2 report or ISO 27001 is a strong signal a vendor takes security seriously. Its absence is not automatically disqualifying for a small tool, but its presence is reassuring.
- Where is our data stored, and is it encrypted? You want data encrypted in transit and at rest, and to know the region, which matters for privacy obligations under PIPEDA and data residency.
- Will you sign a data processing agreement? A DPA is a written commitment on how they handle your data. A serious business vendor has one ready; reluctance is a flag.
- How would you tell us about a breach, and how fast? You need to know you would be told promptly, because your own notification duties depend on it.
- Can we get our data out and leave cleanly? Export and deletion on exit protects you from lock-in and lingering copies.
The red flags
Watch for a vendor that cannot answer basic security questions, has no security or privacy information on its site, will not sign a DPA, is vague about where data lives, or makes leaving difficult. None of these is proof of danger, but each is a reason to look harder before you trust them with anything sensitive.
Keep a simple record
You do not need a big system, just a short list of your important vendors, what data each holds, and a note that you checked. That record is the backbone of a light privacy management program and makes answering a client's or insurer's questions about your supply chain straightforward.