Every new software tool your company adopts needs a security review. Someone has to answer the same questions every time: Is the vendor SOC 2 certified? Where is our data stored? Who else touches it? And, more and more often, will they train AI models on our data?
Most of those answers are already published on the vendor's own website, scattered across a trust center, a privacy policy, a subprocessor list and a data processing agreement. This guide shows what to check, where to find it, and how to let an AI agent do the first pass in seconds.
What a first-pass vendor review covers
| Question | Where vendors usually publish the answer |
|---|---|
| Which security certifications do they hold? | Trust center or /security page |
| Will they train AI on our data? | AI policy, trust center or privacy policy |
| Who are their subprocessors? | /subprocessors or /legal/subprocessors |
| Is there a data processing agreement (DPA)? | /dpa or the legal section |
| Where is data stored? | Trust center, DPA or data residency page |
| How do we report a security issue? | /.well-known/security.txt |
| Do they publish uptime and incidents? | status.vendor.com |
The certifications that matter
- SOC 2 Type II: an independent auditor tested the vendor's security controls over a period of time, usually 6 to 12 months. This is the most common requirement for US software vendors. SOC 2 Type I only checks that controls existed on one day, so it's weaker.
- ISO/IEC 27001: the international standard for an information security management system. 27017 and 27018 add cloud security and cloud privacy, 27701 adds privacy management, and 42001 covers AI management systems.
- HIPAA, PCI DSS, FedRAMP: only relevant if you handle health data, card payments or US government data.
- GDPR and CCPA: privacy laws, not certifications. Vendors mention them to say they comply.
A logo on a website is a claim, not proof. For anything important, ask the vendor for the actual SOC 2 report (usually shared under NDA) or the ISO certificate.
The AI training question
This is the newest and most common question in 2026 reviews. Read the exact wording, because vendors often draw lines like these:
- "We do not train on customer data": the clearest answer.
- Business vs. consumer plans: many vendors don't train on business or enterprise data but may use data from free or consumer plans.
- Opt-out: "we may use your content to improve our models unless you opt out" means training is on by default.
- Subprocessors: a good policy also says the AI providers it uses (for example a model provider) are contractually barred from training on your data.
When statements conflict between pages, trust the more specific one (an AI policy or DPA) and confirm in writing.
Subprocessors and the DPA
A subprocessor is any company the vendor uses that can touch your data: cloud hosting, email delivery, support tools, AI model providers. GDPR requires vendors to list them and tell you when the list changes. Check whether any subprocessor is a dealbreaker for your company, for example a provider in a country you can't send data to.
The DPA is the contract that covers how the vendor processes personal data on your behalf. Most B2B vendors publish a standard DPA you can sign.
Let an AI agent do the first pass
Clicking through five pages for every vendor is slow. Stormap's free MCP server has a vendor_trust_profile tool that reads a vendor's public pages and returns a structured summary:
- certifications the vendor claims, with the page each claim came from
- the AI-training statement, quoted, with a link
- the subprocessor list, DPA link and data residency regions
- security features (SSO/SAML, SCIM, MFA, encryption, pen tests, bug bounty)
security.txtcontact, status page, and a 0–100 transparency score
Connect it to Claude Code with:
claude mcp add --transport http stormap https://stormap.ai/mcp
Then ask: "Do a first-pass security review of these five vendors and flag any that might train AI on our data." In Claude (web or desktop), add https://stormap.ai/mcp as a custom connector. Setup for other apps is on the developers page.
To keep an eye on vendors after you sign, the company_changes tool tracks their pricing, terms, privacy and subprocessor pages and reports what changed and when.
What an automated first pass can't do
- It can't verify certifications. It reports what the vendor claims. Request the audit report for anything critical.
- It only sees public pages. Some trust centers load with JavaScript or sit behind a login; the summary will say when it couldn't read a page.
- It doesn't replace your questionnaire. Use it to skip the obvious questions and focus your review on the gaps.
Quick checklist
- Run the first pass (by hand or with an agent).
- Confirm SOC 2 Type II or ISO 27001 for anything that stores sensitive data.
- Read the AI-training statement word for word, for your plan type.
- Check the subprocessor list for dealbreakers.
- Sign the DPA.
- Request the SOC 2 report or certificate if the data is sensitive.
- Watch for changes to terms, privacy policy and subprocessors after you sign.