← All posts
Security

The 5 Things a Customer's Security Review Checks First

When an enterprise buyer runs security review on your startup, a handful of things decide how the deal goes. Here's what they look at before anything else.

When you sell to a company bigger than yours, at some point their security team gets a vote on the deal. That review can feel like a black box — a long questionnaire, a nervous wait, and a yes or no that lands weeks later.

It's less mysterious than it looks. Most reviews start by checking the same few things, and they're the same things that make or break the timeline. Here's where the attention goes first.

1. Do you have a report, or just answers?

The first question is whether you can hand over evidence instead of assurances. A SOC 2 report (or a serious readiness posture, clearly explained) short-circuits a huge amount of back-and-forth. Without one, every claim becomes a follow-up question.

You don't always need the report on day one — but you need a credible, honest story about where you are and when you'll have it.

2. Who can touch customer data?

Reviewers want to know access is intentional. Expect questions about MFA, least-privilege, and how access is granted and removed. The unspoken test: can you show that a former employee loses access, and that not everyone is an admin?

3. How does code get to production?

They're checking whether changes are reviewed before they ship and whether you'd notice something going wrong. You don't need a heavyweight process — you need a consistent one you can describe and evidence.

4. What happens when something breaks?

Every reviewer knows incidents happen. What they're really assessing is whether you'd detect one, respond in an orderly way, and tell affected customers. A short, real incident process beats an elaborate one nobody has read.

5. Who are your subprocessors?

The data you hold often flows to other vendors — your cloud, your analytics, your support tools. Buyers want a clear list and evidence you've done basic diligence on them. A tidy subprocessor list signals you understand your own data flows.

The pattern

Notice what these have in common: none of them are about having the fanciest security stack. They're about being able to show, clearly and honestly, that you've thought about the basics and can prove it. Teams that can do that turn a scary review into a formality.

If a customer review is coming and you want a read on what they'll flag, we can help you get ahead of it.

Preparing for SOC 2 or building a security program? Schedule a consultation and we’ll help you find the next practical step.