Reusable decision kit
Vendor evidence request
A consistent request for the facts behind security, privacy, administration, change, and exit claims.
What the completed kit should do
The comparison distinguishes verified evidence from statements, assumptions, and unknowns.
Capture these facts in your approved system
- Exact product, plan, deployment model, region, configuration, and connectors
- Identity, access, administration, audit, security, incident, and support evidence
- Data use, retention, training, review, subprocessors, deletion, and export evidence
- Availability, accessibility, change notice, versioning, termination, and portability
- Source, date, evidence type, owner, gap, and required follow-up
Use the structure in this order
- 01
Define the actual configuration being evaluated.
- 02
Send the same material questions to each candidate.
- 03
Classify evidence and log unknowns.
- 04
Convert gaps into controls, terms, tests, constraints, or no-go decisions.
Close the evidence loop
Material claims have dated evidence or are visibly recorded as unresolved decision risk.
Keep sensitive material out of this site
- Do not publish confidential vendor responses or assessment material.
- A certification does not prove the product fits the workflow or configuration.
- Use qualified reviewers for contract, assurance, privacy, accessibility, and security conclusions.