How to use this: one worksheet per vendor, filled in as you evaluate — not after. Sections reference lessons in Module 4. For a repeatable workflow across many vendors, see Vesta. Print → Save as PDF gives you a clean copy; site navigation is hidden in print.

1. Scope and Stakes (lesson 4.3)

Vendor / product
What it touches (data, systems, access level)
Blast-radius tier if it fails or is compromised☐ Tier 1 — we stop operating / customers exposed   ☐ Tier 2 — painful degradation   ☐ Tier 3 — annoyance
Down for 6h / 24h / a week — what happens?
Compromised — what does the attacker get?
Could we leave in 90 days? What would it take?
Their critical sub-processors (vendors of the vendor)

2. The SOC 2 Pass (lesson 4.1)

Report type / period covered / bridge letter?
Trust criteria in scope — do they cover what we care about?
Product we're buying is actually in scope?
Exceptions noted + management response
Carve-outs that aren't hyperscalers
CUECs assigned to us — and who confirmed we do them

3. Questions That Can't Be Faked (lesson 4.4)

Redacted example of the real 3 AM alert
Who investigates — team size, time zones, median tenure
Last serious miss, and what it changed
Median alert-to-human-triage time — and when the clock starts
References: two customers our size, one that left — why do customers leave?

4. Contract Terms (lesson 4.4)

  • Pilot on our telemetry, with success criteria we defined, before annual commitment
  • Termination for convenience (target: 90 days' notice), even with a penalty
  • Quality SLA — triage time and escalation criteria, not just uptime
  • Breach notification to us within a defined window (target: 72 hours)
  • Data returned in a usable format at exit; deletion certified
  • Auto-renewal removed, or renewal notice ≥ 60 days before the deadline
Terms we traded away — and why

5. Decision

Decision / date / decided by
What tipped it
Revisit date (renewal minus 90 days)