Skip to content

Reusable decision kit

Vendor evidence request

A consistent request for the facts behind security, privacy, administration, change, and exit claims.

TARGET OUTPUT

What the completed kit should do

The comparison distinguishes verified evidence from statements, assumptions, and unknowns.

FIELDS

Capture these facts in your approved system

  • Exact product, plan, deployment model, region, configuration, and connectors
  • Identity, access, administration, audit, security, incident, and support evidence
  • Data use, retention, training, review, subprocessors, deletion, and export evidence
  • Availability, accessibility, change notice, versioning, termination, and portability
  • Source, date, evidence type, owner, gap, and required follow-up
SEQUENCE

Use the structure in this order

  1. 01

    Define the actual configuration being evaluated.

  2. 02

    Send the same material questions to each candidate.

  3. 03

    Classify evidence and log unknowns.

  4. 04

    Convert gaps into controls, terms, tests, constraints, or no-go decisions.

DONE WHEN

Close the evidence loop

Material claims have dated evidence or are visibly recorded as unresolved decision risk.

CAUTION

Keep sensitive material out of this site

  • Do not publish confidential vendor responses or assessment material.
  • A certification does not prove the product fits the workflow or configuration.
  • Use qualified reviewers for contract, assurance, privacy, accessibility, and security conclusions.