Something you can put through a review
You are not evaluating software. You are evaluating a single supplier holding a principal’s entire data estate, and you have to write something defensible about it.
The answers are published, not promised
Which keys I hold and which the client holds, what an administrator can technically read, where the hardware physically is and what that does not give you — all of it in writing, before you ask.
Key-person risk, answered with a mechanism
Death, incapacity, insolvency and termination are treated separately, each with the arrangement that covers it — not a reassurance. The client can operate without me on any day of the contract.
Service levels with a consequence attached
Severity definitions, response targets, support hours stated honestly for a single operator, and what happens when I miss them — including the exit.
No certification, and no pretending
There is no ISO 27001 and no SOC 2. If your committee requires an auditor’s letter, I am not your supplier and I will say so on the first call rather than the fourth.
Company identification, VAT and REA numbers are here, so you can verify the entity before you speak to it.
Send the diligence questions