Use these questions to obtain written, comparable answers from every vendor. Binding answers should be included in procurement documents and the agreement.
1. Governance and assurance
Which security standard or framework applies, and what is the certification scope?
When was the latest audit and who performed it?
Who owns information security, privacy and incident response?
How are risks, exceptions and material changes managed?
2. Identity and access
Are SSO, SAML or our identity provider supported?
Is MFA available for administrators and sensitive users?
How are roles, least privilege and segregation of duties implemented?
How is access revoked when an employee or administrator leaves?
3. Data and privacy
Which data categories are collected by each attendance method?
Where is data stored and which subprocessors handle it?
How is data encrypted in transit and at rest?
What are the retention, export and deletion rules?
How is biometric data handled when included in the configuration?
4. Availability and incidents
Which availability, backup and recovery objectives are offered contractually?
How does reporting work during an outage or connectivity loss?
What is the incident-notification process and contractual timeline?
How are business-continuity and disaster-recovery plans tested?
5. Development, monitoring and vendors
How are code, dependencies and vulnerabilities tested before release?
Which monitoring, logs and alerts exist, and how long are they retained?
Which material subprocessors are used and how are changes communicated?
How can a customer review test findings or security documents under NDA?
Your privacy choices
We use measurement only after your approval. Essential storage keeps your preference and campaign source. Learn more