Xeneural
BlogSecurity

The security you inherit: the ten questions a buyer should ask their software vendor

When you contract cloud software you do not buy security: you inherit it. These ten questions separate a vendor who has it settled from one who improvises it.

Corridor of a data center with closed server cabinets

A company that installs its own server decides everything: where it is, who touches it, how it is backed up. A company that contracts cloud software decides none of that. It inherits it from the vendor. That is why the buying conversation should spend as much time on security as on price, and it almost never does, because nobody knows what to ask.

These are the ten questions a buyer should ask. They are grouped in four blocks, and each one comes with the answer you should hear. You do not need to be technical to ask them or to judge the answers.

Where your data lives

  • 1. In how many regions is my information replicated? The right answer is more than one. If a region goes down, the operation continues from another.
  • 2. Are traffic and storage encrypted? Both, always. In transit between your browser and the server, and at rest on disk.
  • 3. Who at the vendor can see my data, and under what control? There must be a short list, with access logged and reviewable.

A vendor who answers by naming the brand of their cloud has not answered. The brand does not matter; how it is configured does. XEN replicates each organization's data across several regions and encrypts all traffic and all storage, with no exceptions by plan.

What happens when something fails

  • 4. How often are backups taken and to what moment can I go back? The useful answer is point in time recovery, not a weekly copy.
  • 5. What availability commitment do you sign? A number, in writing, in the contract. XEN commits to 99.9% with an SLA.
  • 6. How is the service protected against attacks at the network edge? There must be a layer that absorbs malicious traffic before it reaches the application.

The fifth question tends to make people uncomfortable, and that discomfort is information. A vendor who will not sign an availability commitment has not measured theirs.

Who can see what

  • 7. Are permissions per organization, per module and per action? A salesperson should not be able to open accounting, and an accountant at one company in the group should not see the other.
  • 8. Is every action recorded with its author? View, create, edit, approve, delete. All of it, with date and person.
  • 9. Does the artificial intelligence inherit the user's permissions or have its own? If it has its own, it is the back door to the whole system.

The ninth question is new and it is the most important of this decade. An assistant with access to everything turns any permission scheme into decoration: you just ask it instead of opening the locked screen. In XEN, Xeni answers with the permissions of whoever asks, and the actions agents propose wait for approval when they matter.

What the vendor signs

  • 10. What contractual commitments do you offer a large company? A contract with an SLA, a data processing agreement, and documentary support when your auditor asks.

This last one turns everything above into something enforceable. The first nine describe how the service works; the tenth says what happens if it stops working that way. A serious vendor has the three documents ready and hands them over without being pressed.

How to use this list

Send it in writing before the sales meeting and ask for the answers in writing. Not because the salesperson would lie in person, but because a written answer can be attached to the contract. And if any question gets a no, ask when it will stop being a no. A vendor who knows their limits and has a plan is better than one who says yes to everything.

XEN's answers to these ten questions are published on the platform's security and cloud pages, in the same order. See the platform's security

ShareLink copied