Vetting a New Software Vendor Before You Sign

Before you hand a vendor your client files, run the same diligence you would run on any supplier. Here are the questions that actually matter.

A laptop screen showing rows of encrypted data and a security dashboard
Photo: Wikideas1 / Wikimedia (CC0)
Jump to section
  1. What Security Certifications Should I Ask For?
  2. Who Owns the Data and How Do I Get It Back?
  3. Where Is the Data Stored and Processed?
  4. What Happens If the Vendor Is Breached?
  5. How Do I Leave If It Does Not Work Out?
  6. Turning Questions Into a Habit

A sales rep sends a slick demo, a friendly quote, and a link to start a free trial by Friday. It is easy to forget that you are about to hand a stranger the most sensitive thing your firm holds: your clients' files. You would never take on a new courier or accountant without a few pointed questions. Software deserves the same scrutiny, and often more, because the risk is invisible until something goes wrong.

The good news is that you do not need a technical background to vet a vendor well. You need a short list of the right questions and the discipline to insist on real answers before you sign. Treat this as the diligence you would run on any supplier, and treat vague replies as a warning sign. What follows is the FAQ I wish every firm kept handy during a procurement call.

What Security Certifications Should I Ask For?

Start here, because it filters out the amateurs quickly. Ask whether the vendor has completed an independent security audit, and ask to see the report or at least a summary. The most common one for cloud software is a SOC 2 Type II report, which describes how a third party tested the controls the vendor claims to have. Some vendors will also point to ISO 27001. Either is a reasonable signal. A vendor that has never been audited is not automatically disqualified, especially a small one, but you should expect a thoughtful explanation rather than a blank stare.

Do not stop at the logo on the marketing page. A certification covers a defined scope and date range, so ask which systems it covers and when it was last renewed. Ask about encryption in transit and at rest, and how staff access to your data is controlled internally. If you are tightening up firm security generally, our note on multi-factor authentication for the whole firm pairs well here, since your vendor should support it too.

Tip. Ask the vendor to send answers in writing, by email, and keep them. If a security promise matters enough to influence your decision, it matters enough to have on record if the promise is ever broken.

Who Owns the Data and How Do I Get It Back?

This is the question that separates a supplier from a trap. Read the contract, not the sales deck. You want a clear statement that your firm owns its data and that the vendor is merely holding it on your behalf. Watch for language granting the vendor broad rights to use, analyze, or share your content, especially anything about training models on customer data. For a law firm, that last point can collide with your confidentiality obligations.

Then ask the practical version: how do I get my data out, in what format, and how fast? A good answer includes self-serve export to open formats like CSV or PDF, not a support ticket that takes three weeks and produces a proprietary file nobody else can read. Our piece on client confidentiality with cloud tools goes deeper on the professional-responsibility side.

Data ownership means nothing on paper if you cannot actually pull the files out the door. Vendor diligence, rule one

Where Is the Data Stored and Processed?

For a Canadian firm this is not a trivia question. Ask where the data physically lives and where it is processed. Some clients, and some regulators, care whether files stay in Canada. Public-sector and health-adjacent work often comes with residency expectations, and even where the law does not strictly require Canadian storage, a client may. Better to know up front than to discover a US data centre in the middle of a sensitive matter.

Ask about subprocessors too. Most modern software is assembled from other services, so your vendor almost certainly relies on a hosting provider and several tools behind the scenes. A mature vendor publishes a list of subprocessors and tells you when it changes. If they cannot name who else touches your data, they cannot really answer the residency question either.

QuestionA good answer sounds likeA red flag sounds like
Where is our data stored?"Canadian region, and here is the documentation.""Somewhere in the cloud, it is very secure."
Who else can access it?"Here is our subprocessor list, updated when it changes.""Just us." (with no detail)
Can we export everything?"Yes, self-serve, in CSV and PDF, anytime.""Open a ticket and we will see."

What Happens If the Vendor Is Breached?

Assume it will happen to someone, someday, and ask how the vendor behaves when it does. The key questions are simple. Will you tell us, and how quickly? What is your notification commitment in the contract? Under Canadian privacy law you may have your own reporting obligations if client data is exposed, and you cannot meet them if your vendor sits on the news for a month. Ask for a specific timeframe in writing, and ask what support you will get during the incident.

Their track record helps too. Have they had a breach before, and what did they do about it? A vendor that has handled an incident transparently is often safer than one that claims it could never happen. Pair this with your own preparation, because a breach on their side can still mean lost access on yours. A simple backup and recovery plan keeps you from depending wholly on one supplier's uptime, and knowing how to spot phishing at a firm reduces the chance the breach starts with your own staff.

Warn. If a vendor's contract is silent on breach notification, that silence is the answer. Get a defined notification window added before you sign, or keep shopping.

How Do I Leave If It Does Not Work Out?

Nobody wants to talk about the exit during the honeymoon, which is exactly why you should. Ask what happens to your data when you cancel. How long do they keep it, when do they delete it, and can you get a full export on the way out? A trustworthy vendor makes leaving easy because they are confident you will stay. The ones that make offboarding painful are telling you something.

Watch the commercial terms too. Look for auto-renewal clauses, long notice periods, and price hikes buried in a renewal schedule. Ask whether they help with migration or at least hand over clean data a competitor can import. Our take on integrations that save time is worth a read, because a system that connects to open standards is usually easier to leave than a walled garden. Tools built for firms, including A1 CMS, should let you export your matters, clients, and billing without a fight.

Turning Questions Into a Habit

You do not need a hundred-page questionnaire. You need five honest questions and the discipline to notice how the answers are given. Confident, specific, written answers are a green light. Deflection, jargon, and "trust us" are a signal to slow down. Save the list, reuse it for the next tool, and you will build procurement judgment that protects the firm without slowing it to a crawl. For more on choosing tools without losing control, the legal tech and AI hub and my author page collect the rest of this series, and our legal and privacy page models the kind of clarity you should expect from anyone you sign with.

Priya Natarajan

Legal technology editor

Priya covers where legal work and software meet, with a healthy skepticism for hype and a soft spot for tools that quietly save hours.

Run your firm on one calm platform

Matters, billing, trust accounting, client portal, and automation, together in A1 CMS. Try it free, no card required.