New construction apps arrive constantly: scheduling, safety, field reporting, estimating, equipment tracking and more. Each promises efficiency, and each wants access to your data and often your other systems. Most contractors evaluate features and price carefully and security barely at all.
A short vendor security questionnaire fixes that. You do not need a technical background to use it. You need to ask clearly and judge whether the answers are specific.
Why ask
When you adopt a platform, you trust it with project files, financial details, employee information and sometimes customer data. A weakness at the vendor can become your incident. Prime contractors, owners and insurers also increasingly ask how you vet your suppliers.
The questions
Access and identity
- Does the platform support multi-factor authentication, and can we require it for all users? Good answers say yes, describe the methods and explain how administrators enforce it.
- Does it support single sign-on with our identity provider? Single sign-on simplifies offboarding and lets you apply your own access policies.
- Can we define roles with limited permissions? You want the ability to give each user only what they need.
Data protection
- How is our data encrypted in transit and at rest? The answer should be specific and not just "we use industry-standard security."
- Where is our data stored, and who can access it at the vendor? Ask about hosting locations and internal access controls.
- Can we export our data, in what formats, and what happens when we leave? A clear answer reduces the risk of lock-in.
Assurance and track record
- Do you have an independent security assessment, such as a SOC 2 report, and can we review it? Vendors may share reports under a confidentiality agreement. If they have none, ask what they do instead.
- How do you handle vulnerabilities and security updates? Look for a defined process, not vague reassurance.
- Have you had a security incident, and how did you notify customers? Honest vendors can describe their process even if they have nothing to report.
Resilience and response
- What are your backup, recovery and uptime commitments, and how will you notify us of an incident? Ask about notification timelines and contacts, particularly if you have contractual reporting duties.
Reading the answers
Signs of a mature vendor
- Specific, documented answers
- Willingness to share reports or summaries
- Clear administrator controls for you
- A defined incident notification process
- Transparency about limits, not just strengths
Signs to be cautious
- Evasive or generic replies
- No MFA or role-based access
- No way to export your data
- Reluctance to discuss security at all
- Pressure to skip review because of a discount or deadline
Consider the integrations
Many apps ask to connect to your accounting, project management or email systems. Each connection extends trust. Before approving:
- Review exactly which permissions the app requests
- Grant the minimum access necessary
- Assign an owner who can disconnect the integration later
- Record the connection in your software inventory
Match the effort to the risk
Not every tool needs a deep review. A calendar widget is not the same as a platform holding payroll data. Consider three tiers:
- Low risk: no sensitive data, limited access. A quick check is enough.
- Moderate risk: project data or employee information. Use the full questionnaire.
- High risk: financial systems, CUI or critical operations. Add contract review, a security report review and an internal approval step.
A hypothetical example
Consider a hypothetical contractor that adopts a free field reporting app because a superintendent likes it. The app has no MFA, shares links publicly by default and cannot export data. Months later the superintendent leaves, and nobody knows who holds the account or where photos and reports are stored. A fifteen-minute questionnaire would have flagged the problems before adoption.
Make it routine
Keep the questionnaire as a one-page form. Require it before any new tool gets company data, store the answers with the contract and revisit them annually for important systems.
Getting a second set of eyes
Ironfield Cyber helps contractors and energy companies evaluate construction software and integrations, review vendor reports and set simple approval processes. If you are considering a new platform, we can help you ask the right questions before you commit.