The vendor security review has started asking for proof

Enterprise buyers used to ask whether you kept audit logs. Now they ask who can edit them. What changed in procurement, and what to have ready before the deal.

If you sell software to companies, there is a document that arrives before the contract does: the vendor security questionnaire. For years it was a ritual both sides performed with mild embarrassment — a spreadsheet of yes/no questions, answered optimistically, filed unread.

The spreadsheet is still there. The questions inside it have been quietly changing, and the change says something about where B2B software is heading.

From “do you have it” to “who can touch it”

The older generation of questions established existence: do you encrypt at rest, do you support SSO, do you keep audit logs. Reasonable questions, and by now table stakes — nearly every vendor answers yes to all of them, which is exactly why the answers stopped differentiating anyone.

The newer generation establishes integrity and authority. Who can modify or delete your audit logs, and would you know if they did? How are your own administrators’ actions on our data recorded, and who approves them? When you say a record wasn’t altered, what does that claim rest on besides your word? Can we get evidence of a specific event, in a form our auditors will accept from a third party?

These are harder questions, and they are harder on purpose. Buyers have sat through enough incidents — their own and their vendors’ — where the post-mortem stalled on the vendor’s logs being incomplete, editable, or gone. A breach at a supplier becomes the customer’s disclosure problem, so the customer’s security team has learned to ask in advance what the forensics will look like. The questionnaire is where that lesson lands.

The checkbox era priced itself out

There is a second force at work: the compliance badge stopped carrying information. When a SOC 2 report became something a startup could assemble in weeks with an automation platform, having one went from signal to prerequisite. The logo on the website opens the door; it no longer wins the room.

What wins the room has shifted to demonstration. Not “we have audit logging” but here is the trail of an admin action, here is the approval attached to it, here is the verification failing when we tamper with a record on purpose. A claim any vendor can make versus an artifact only a prepared vendor can show.

Why this is good news for small vendors

The instinct is to read rising security bars as favoring incumbents, who have compliance departments. The opposite is often true at the demonstration layer.

A large vendor answers the hard questions the way large organizations answer anything: three weeks, four teams, and a carefully hedged paragraph approved by legal. A small vendor whose product was built with the evidence layer in place can answer in a meeting, on screen, in minutes. Procurement teams notice the difference — not because the small vendor’s paragraph is better, but because speed and specificity of proof is itself the signal. It is one of the few remaining places where engineering rigor converts directly into sales velocity, which is a rare alignment worth exploiting.

What to have ready

If the harder questionnaire has not reached you yet, it will. The preparation compounds if it starts before the deal is on the table:

  • A one-page answer to who can modify what, including your own admins and your own database access — the honest version, because the follow-up call will find the dishonest one.
  • The approval trail for privileged actions: not the policy saying approval is required, but where an actual approval is recorded and how long it survives.
  • A tamper story you can demo: what happens, concretely, when a record is altered out-of-band. If the answer is “nothing notices,” that is the gap to close before a prospect finds it for you.
  • Evidence export: the incident-day artifact a customer’s auditor would accept. Producing it calmly in a sales call is the whole pitch.

The security review is tedious, and it is also the one sales document written by the people your product’s integrity actually has to convince. Treat it as the spec it quietly is.


Axowl gives vendors the demonstrable answer — sealed identity, approval, and audit events with verification a customer can run. See how it works.