Due diligence on a SaaS vendor
What to ask, what to ask for in writing, and what should stop the deal — before you sign for a piece of software your team will depend on.
Most of what a vendor tells you in a demo is true and useless: it describes the product working. Diligence is about the days it does not. Every item below asks for something a vendor can hand over in a week if it exists, and cannot produce at all if it does not — which is the answer you are buying.
What it actually costs
The list price is rarely the price. Ask for the total of everything you will be invoiced for in year one and year three.
What will we be invoiced in year one, and in year three?
Deal-stopperSeat price, onboarding, migration, premium support, sandbox environments and overage charges are often quoted separately, and the ones that grow are rarely the ones in the headline.
Ask for: An itemised quote covering every line, with year-three pricing under your expected growth.
Red flags
- Only a per-seat figure offered
- Onboarding cost unstated
- Overage rate not disclosed
What caps the price at renewal?
Deal-stopperAn uncapped renewal on a product your team has standardised on is a price you no longer negotiate.
Ask for: The renewal clause, with a stated cap or index.
Red flags
- No cap
- Cap applies only to the first renewal
- Auto-renewal with a short notice window
What is the term, the notice period, and what happens if we stop paying mid-term?
ImportantNotice periods that expire before you would normally review the contract are how a one-year commitment becomes three.
Ask for: Term, auto-renewal and termination clauses.
Red flags
- Notice window shorter than 60 days
- Termination for convenience unavailable at any price
Can we run a paid pilot on production data, and what does it cost to stop?
ImportantA pilot that cannot touch real data tests nothing you care about.
Ask for: Pilot scope, duration, and the exit terms in writing.
Red flags
- Pilot requires the full annual commitment
- Pilot data cannot be exported
Whether it stays up
Ask for numbers with dates attached. A vendor that measures its own uptime can produce them in minutes.
What was uptime over the last 90 days, and where is that published?
Deal-stopperA status page with history is a standing, checkable claim. A number in a slide is not.
Ask for: A public status page showing at least 90 days of history, including incidents.
Red flags
- No status page
- Status page shows only the current state
- History resets after an incident
Is an uptime level committed in the contract, and what is the remedy?
Deal-stopperMarketing pages promise 99.9%; contracts often promise nothing. Where an SLA does exist, the remedy is usually a service credit worth a fraction of your loss — which is worth knowing before rather than after.
Ask for: The SLA clause itself, not the marketing page, with the credit schedule and how you claim.
Red flags
- Uptime promised only in marketing
- Credits require a claim within days
- Exclusions swallow the commitment
How many major incidents in the last 90 days, and can we read the post-mortems?
ImportantIncidents are normal. Published post-mortems tell you whether the vendor learns, and a vendor that writes them is telling you it has an engineering culture that can.
Ask for: Incident history with dates, duration and written post-mortems.
Red flags
- No incidents claimed at all
- Post-mortems private
- Incidents described without duration
When are maintenance windows, and are they excluded from the uptime figure?
ImportantPlanned downtime excluded from the SLA can make a poor availability record look spotless.
Ask for: The maintenance policy and how it interacts with the SLA.
Red flags
- Unbounded maintenance exclusion
- Windows fall in your working hours
Security you can check
Certification names are easy to print. Each one below has a register, a number or a report behind it — ask for that, not the logo.
Which security certifications are current, and what is the certificate number and scope?
Deal-stopperAn ISO 27001 certificate covers a defined scope, which is sometimes a head office and not the product. Certificates are checkable against the registrar; logos are not.
Ask for: Certificate number, registrar, scope statement and expiry date — then check it on the registrar's register.
Red flags
- Logo with no certificate
- Scope excludes the product
- Expired or 'in progress'
Is the SOC 2 report Type I or Type II, and what period does it cover?
Deal-stopperType I says controls were designed on one day. Type II says they operated over a period. They are routinely quoted as if they were the same thing.
Ask for: The report itself under NDA, with the observation period and any qualifications.
Red flags
- Type I presented as SOC 2 without qualification
- Report older than 12 months with no bridge letter
- Exceptions not discussed
Who ran the last penetration test, when, and will you share the summary?
Deal-stopperCadence and independence matter more than the result. A vendor that tests annually with a named third party is making a standing commitment.
Ask for: Testing firm, date, scope and a remediation summary.
Red flags
- Self-tested only
- No test in the last 12 months
- Summary refused even under NDA
Which of SSO, SCIM, MFA enforcement, role-based access and audit logs are available, and on which plan?
Deal-stopperThese are frequently real but reserved for the top tier, which changes the price you are actually comparing.
Ask for: A feature-by-plan answer in writing.
Red flags
- SSO only on enterprise at a large premium
- No audit log export
- Roles cannot be scoped
Is there a published vulnerability disclosure policy?
Worth askingIt tells you whether a researcher who finds something has somewhere to send it, which is the difference between a quiet fix and a public one.
Ask for: A security.txt file or a published disclosure page.
Red flags
- No route to report
- Legal threats in the policy
Your data, while you are a customer and after
Every item here should be answerable from documents the vendor already has. If they have to write something new, that is the finding.
Is there a data processing agreement, and what is the transfer mechanism?
Deal-stopperIf the vendor processes personal data on your behalf you need one, and if data leaves your jurisdiction you need a lawful basis for the transfer.
Ask for: The DPA, with the transfer mechanism and any standard contractual clauses attached.
Red flags
- DPA on request only and not produced
- Transfers unaddressed
- DPA cannot be signed before purchase
Who else processes our data, where, and how much notice do we get before that changes?
Deal-stopperA sub-processor is a supplier you did not choose but remain accountable for. The notice period is what gives you the chance to object.
Ask for: A published sub-processor list with locations, purposes and a stated notice period for changes.
Red flags
- No published list
- Changes without notice
- Locations unstated
Where is data stored, and can we pin it to a region?
ImportantRegional pinning is often available but not default, and not always for backups and logs as well as primary storage.
Ask for: Named regions for primary storage, backups and logs.
Red flags
- Region applies to primary data only
- Backups in an unnamed region
How quickly are we told about a breach, and is that in the contract?
Deal-stopperYour own regulatory clock starts when you become aware. A vendor's notification timeline sets it.
Ask for: The notification clause with a stated period.
Red flags
- 'Without undue delay' with no period
- Notification at the vendor's discretion
What is deleted on termination, when, and how is that confirmed?
ImportantDeletion from the live system is not deletion from backups, and the gap is usually where the honest answer lives.
Ask for: Retention schedule, deletion timetable including backups, and a certificate of deletion on request.
Red flags
- Indefinite retention
- Backups excluded from deletion
- No confirmation offered
Getting out
The cheapest time to plan an exit is before you sign, and the answer shapes how much of your business you are willing to put inside.
Can we export everything ourselves, in a documented format, without asking?
Deal-stopperAn export that requires a support ticket is an export the vendor can slow down at the exact moment you need it fast.
Ask for: Self-service export covering records, attachments, history and configuration, with the format documented.
Red flags
- Export by support request only
- Attachments or history excluded
- Proprietary format with no schema
What is the API versioning and deprecation policy, and what are the rate limits?
ImportantIf you build on it, the deprecation notice period is the real measure of how much rework the vendor can force on you and when.
Ask for: A published versioning policy with a minimum deprecation notice, and documented limits.
Red flags
- No versioning policy
- Breaking changes without notice
- Limits undocumented or per-negotiation
What are the backup RPO and RTO, and when was restore last tested?
ImportantBackups nobody has restored are a belief, not a control.
Ask for: Stated RPO and RTO and the date of the last restore test.
Red flags
- Backups described without a restore test
- No stated RPO/RTO
Whether the vendor will still be here
Public record answers most of this without asking, and the parts you have to ask for tell you how the vendor handles an awkward question.
What is the legal entity, where is it registered, and are its accounts filed and current?
ImportantThe contracting entity is sometimes not the company whose brand you are buying, and filing history is free to check.
Ask for: Registration number and the registry record.
Red flags
- Contracting entity differs with no explanation
- Accounts overdue
- Entity incorporated very recently
Who owns the business, and is a sale or raise in progress?
Worth askingOwnership changes reset roadmaps, support and pricing. You will not always get an answer, but the way it is declined is informative.
Ask for: An ownership statement, and the registry's record of persons with significant control where one exists.
Red flags
- Ownership not disclosed at all
How often does the product ship, and where is the changelog?
ImportantA public changelog with dates is a running record of whether the roadmap you were shown is being built.
Ask for: A dated public changelog or release notes.
Red flags
- No changelog
- Long unexplained gaps
- Releases described only in sales conversations
What are support hours, channels, and the first-response target for a critical issue?
Deal-stopperCoverage that does not overlap your working day is the most common unpleasant surprise in the first month.
Ask for: Support hours by plan, channels, and the committed first-response time for the top severity.
Red flags
- No committed response time
- Critical support only on a higher tier
- No overlap with your hours
References worth taking
Vendor-supplied references are selected. Ask for the ones that are harder to select.
Can we speak to a customer in our sector, at our size, who has been live for more than a year?
ImportantA reference at a different size solves a different problem than the one you are about to have.
Ask for: Two matched references, live for over twelve months.
Red flags
- Only recent customers offered
- References all from one sector unlike yours
Can we speak to a customer who left?
Worth askingAlmost no vendor says yes, and the reaction to the question tells you a great deal. Where a vendor does say yes, take it — it is the most useful call you will have.
Ask for: A named former customer, or a straight account of why one cannot be offered.
Red flags
- Claim that nobody has ever left
Ask every reference: what broke, how long did it take, and what do you wish you had asked?
Worth askingReferences are prepared to praise. They are rarely prepared for a specific question about failure, and that is where the useful answers are.
Ask for: Your own notes.
Red flags
- Reference cannot name a single problem
This checklist is general guidance, not legal, security or financial advice, and it does not replace your own advisers on anything contentious. It was last reviewed on 19 September 2026. Tell us if something here is wrong or missing.