Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

A twelve-person bookkeeping firm moved its client document collection into a new portal in the spring. It worked well enough. In June a staff member left, and nobody could say which of the logins she held, whether her account was still live, or where the client files actually sat — inside the portal, or with the storage company the portal vendor subcontracts to.
Nothing was stolen. That is not the point. The point is that a business handed over its clients' financial records without ever asking four questions that take ten minutes to ask, and then found it could not answer basic questions about its own accounts.
You do not need to become a security specialist to avoid this. You need a short list of questions, a habit of asking them in writing, and a rule about who gets access to what. Everything below is a judgement framework, not a compliance exercise.
Who This Guide Is For
Owners and managers at companies without a security hire, who are choosing tools that will hold customer records, financial data, or staff information, and who want to know what to ask before signing rather than after.
Editor’s take: Three things this guide doesn't cover but you should know: (1) document your actual workflow before buying; (2) ask the vendor for a 30-day pilot, not a 14-day trial; (3) set a hard review date — six months is the magic window. Tackle those after you finish the steps above.
For non-technical buyers the questions that matter are simple and unglamorous: who can access your data, is MFA enforced, how are backups handled, and can you export everything. Ask for the security documentation rather than taking marketing claims. A vendor that cannot answer clearly is the answer.
Ask these in writing, before the contract is signed, while you still have the sales rep's attention. Four questions, and the way they are answered tells you more than any badge in a website footer.
Where does our data sit, and who else handles it? Which country or region is it stored in? Is it encrypted while moving and while stored? Do you use other companies to store or process it, and can we see that list? Most vendors keep a public list of these sub-processors. If they do not, ask them to send one. You cannot answer the same question from your own customers if you never asked it.
Can we get everything out? In what format, how complete is the export, does it happen self-service or do you have to ask support, and how long do you keep the data after we stop paying? Then do the thing almost nobody does: start a trial, put in a handful of real records, and export them. Ten minutes tells you whether the exit is a button or a negotiation.
If something goes wrong, how will we hear about it? Not "do you have a status page" — everyone has one. Ask who tells you, how, and whether they commit to telling customers directly or only when asked. The answer you want names a route and a person. The answer you do not want is a paragraph about how much they care.
What happens when we leave? How long until data is deleted, does deletion cover backups, and will they confirm it in writing? Alongside it, ask who inside the vendor can look at your records and when. Support teams sometimes need access to help you; the question is whether that access is logged, limited, and something you can switch off.
Small-business buyers tend to look for a logo on a vendor's security page, feel reassured, and move on. The logo is marketing. What matters is whether the vendor can produce something specific.
A vendor with an independent audit report will usually share it, often after a short mutual non-disclosure agreement. A vendor without one will describe its commitment to security at length. Both replies sound reasonable in an email; only one is evidence.
The signal is not whether the answer is yes. It is whether the answer is concrete. "We encrypt your data" is a sentence anybody can write. "Records are stored in this region, encrypted at rest, support access is logged and requires your approval, and backups are purged within a stated window" is an answer, because you can check it later.
Test the process as well as the content. Send the questions in writing and watch what happens. How long until a reply? Does it come from the sales rep repeating marketing language, or from someone whose job involves security? A company that responds quickly and specifically to a small customer's questions will behave better during an actual incident than one that takes three weeks to say nothing.
Two things count as red flags. A vendor that will not put anything in writing, and a vendor that gets defensive about being asked. Neither is a company you want holding your customer records.
One more question worth slipping in: will you tell us when you add a new sub-processor or move where data is stored? Companies that commit to notifying customers are also the ones that generally know, at any moment, where your data is.
Vendor security matters, and you have limited influence over it. Your own accounts are entirely yours, and this is where most small companies are weakest.
One account per person. Always. A shared login is convenient until something goes wrong and you cannot tell who did it. Shared logins also survive departures, because nobody wants to change a password six people use.
Multi-factor authentication on anything holding money, customer data, or the ability to delete. Ideally everywhere, but start where the damage would be worst. Make it a condition of getting access, not a suggestion in a handbook.
Few admins, but never one. Admin rights should sit with as few people as the work allows, and at least two people should have them, so a departure or a lost phone does not lock the business out of its own systems.
Own tools with a role address, not a person's email. The account that owns your billing, your domain, and your core systems should be something like an admin address your company controls. When the alternative is one employee's address, that employee quietly becomes the key to the business.
Review access on a schedule you will actually keep. Quarterly is common, but the frequency matters less than the trigger. Tie the review to something already happening — month-end, a payroll run, a regular management meeting — or it will be skipped by month two.
Add every new tool to that review. Tools signed up for during a busy week almost never get added to the list, and within a year you have accounts nobody remembers creating, still charging a card.
Most companies have a leaving process for laptops and keys. Very few have one for software, which is why a business of twelve people can end up with live accounts belonging to people who left two years ago.
Revoke on the last day, not at month-end. Every day an account stays open after someone leaves is a day you cannot attribute anything that happens in it.
Transfer ownership before you close anything. Files, documents, scheduled reports, integrations, and billing contacts created under a leaver's account may disappear with it. Move them first, then revoke.
Rotate shared secrets. API keys, integration tokens, shared mailboxes, and any credential the person could have seen. This is the step everyone skips and later regrets.
Check connected applications. Inside the tools the person used, look for third-party apps their account authorised. Those grants often outlive the account that created them.
Take them off billing and vendor contacts. Renewal notices and security alerts going to a dead address is how a subscription quietly lapses or, worse, how a real alert goes unseen.
Archive, then delete. Export what you might need for records or handover, then remove the account. Keeping a former employee's mailbox alive indefinitely is not an archive; it is an unmonitored account.
The risk is rarely that someone picks your company out specifically. It is that an automated scan finds a reused password, or that a client asks you where their records are stored and you cannot answer without guessing. Both happen to small businesses, and neither requires anyone to have heard of you.
Treat the refusal as the answer. A vendor that regularly handles business data will have a standard way of responding, usually a questionnaire or a document they can send. Silence generally means nobody internally owns the subject.
Yes. The useful signal is whether the report exists and whether they will share it, and you can pass it to whoever advises your business on technology or insurance. You do not have to read it yourself for asking to be worthwhile.
Tie the review to something your business already does, such as a month-end or payroll run, because a review that depends on someone remembering will not happen. The interval matters far less than the habit.
It works until they leave and the tool they signed up for holds company records nobody else can reach. Require that every business tool is owned by an address your company controls, and keep a list of what each person has.
Take the ten-point version above and send the first four questions to whichever vendor you are evaluating next. Ten minutes of writing now replaces the conversation you would otherwise have after something goes wrong.
When a tool gets purchased, somebody's account gets created. Six months and three hires later, nobody is sure who owns that login. NordPass gives the team one shared vault with role-based access, an activity log, and a free family plan for every employee.

Every question here is one a buyer can ask before signing. Items that require a security team to execute were left out on purpose, because a small business cannot action them.
The risk is rarely that someone picks your company out specifically. It is that an automated scan finds a reused password, or that a client asks you where their records are stored and you cannot answer without guessing. Both happen to small businesses, and neither requires anyone to have heard of you.
Treat the refusal as the answer. A vendor that regularly handles business data will have a standard way of responding, usually a questionnaire or a document they can send. Silence generally means nobody internally owns the subject.
Yes. The useful signal is whether the report exists and whether they will share it, and you can pass it to whoever advises your business on technology or insurance. You do not have to read it yourself for asking to be worthwhile.
Tie the review to something your business already does, such as a month-end or payroll run, because a review that depends on someone remembering will not happen. The interval matters far less than the habit.
It works until they leave and the tool they signed up for holds company records nobody else can reach. Require that every business tool is owned by an address your company controls, and keep a list of what each person has.