Something you can put through a review

You are not evaluating software. You are evaluating a single supplier holding a principal’s entire data estate, and you have to write something defensible about it.

The answers are published, not promised

Which keys I hold and which the client holds, what an administrator can technically read, where the hardware physically is and what that does not give you — all of it in writing, before you ask.

Key-person risk, answered with a mechanism

Death, incapacity, insolvency and termination are treated separately, each with the arrangement that covers it — not a reassurance. The client can operate without me on any day of the contract.

Service levels with a consequence attached

Severity definitions, response targets, support hours stated honestly for a single operator, and what happens when I miss them — including the exit.

No certification, and no pretending

There is no ISO 27001 and no SOC 2. If your committee requires an auditor’s letter, I am not your supplier and I will say so on the first call rather than the fourth.

Company identification, VAT and REA numbers are here, so you can verify the entity before you speak to it.

Send the diligence questions