Contractors and energy companies buy software constantly: project management, estimating, scheduling, safety, timekeeping, fleet tracking, and document control. Each new application stores your information, connects to your other systems, and creates another set of accounts. A quick vendor security review before purchase takes far less time than cleaning up after a problem.
You do not need to be a security expert to ask good questions. This guide offers a practical review process that scales from a small tool to a core platform.
Decide how sensitive the data is
Match the depth of review to the stakes. A tool that stores public marketing content needs little scrutiny. A platform that holds payroll, banking information, bid pricing, employee records, or controlled information deserves a closer look.
Ask: what data will go into this system, who will use it, and what would happen if it were exposed or unavailable for a week?
Questions about security basics
- Does the platform support multi-factor authentication, and can we require it for all users?
- Does it support single sign-on with our identity system?
- Is data encrypted in transit and at rest?
- What roles and permissions are available, and can we limit access by project, role, or folder?
- What audit logs are available, and can we export them?
If a platform cannot require MFA or provide basic permission controls, that should weigh heavily.
Questions about the vendor's practices
- Do they have an independent security assessment or report, and will they share it under a confidentiality agreement? Many established vendors can provide documentation of their controls.
- How do they handle vulnerabilities and patching?
- Do they perform background checks and security training for staff?
- How do they limit employee access to customer data?
- Do they test their incident response and disaster recovery plans?
Treat vendor documentation as evidence worth reading, not as a guarantee.
Questions about data handling
- Where is the data stored, and can you choose the region?
- Who are the subprocessors and hosting providers?
- How long is data retained after deletion or contract termination?
- Can you export all of your data in a usable format, and how?
- What are the backup and recovery commitments?
- Does the vendor use your data for other purposes, such as analytics or product training?
For contracts involving sensitive government information, check whether additional requirements apply to cloud services that handle it.
Questions about incidents
- How and when will the vendor notify you of a security incident?
- What is their support process during an incident?
- Is there a named contact for security matters?
- What liability and remedies does the contract specify?
Ask for a clear notification commitment in the contract, ideally with a defined timeframe.
Questions about integrations
- What access do integrations receive, and can permissions be limited?
- Are API keys and tokens revocable and scoped?
- Is there a marketplace for third-party apps, and how are they reviewed?
Review the contract
Look at terms on data ownership, confidentiality, security obligations, notification of breaches, service levels, subcontractors, and exit rights. Have counsel review significant agreements. Be cautious of auto-renewals and price escalators, and ensure you can retrieve your data if the relationship ends.
Plan for rollout
Security continues after purchase. Before go-live:
- Configure MFA and permissions deliberately instead of accepting defaults.
- Limit administrators.
- Set data retention and sharing options.
- Connect integrations using dedicated service accounts.
- Train users.
- Document the owner, purpose, and renewal date in your software register.
Revisit annually
Vendors change. Review key platforms each year. Confirm users are current, integrations are still needed, and the vendor's practices have not worsened. Retire tools that are no longer used.
Red flags
- No MFA option.
- Vague or evasive answers about data location and security.
- Refusal to provide any security documentation.
- No export capability.
- Pressure to skip review because of urgency.
Help from Ironfield Cyber
Ironfield Cyber helps contractors and energy companies review software vendors, configure new platforms securely, and keep a register of the applications that hold business data. If you are evaluating a major platform, we can help you prepare the questions and review the answers.