Founding offer: save 20% for life, only 50 places·14-day free trialClaim yours →

Questions to ask any agency software vendor before you trust them with client data

Clients now ask agencies hard questions about data. Most of the answers depend on your software vendors, so ask them first. Here is the template.

The Crewqo team Published Updated 6 min read
On this page
  1. Why agencies need to ask
  2. The template: nine areas, the questions that matter
  3. How to read the answers
  4. Right-size your expectations
  5. How Crewqo answers the core questions
  6. Your vendor review routine
  7. Frequently asked questions

The short answer: before you put client data into any tool, ask about nine things: how your data is kept apart from other customers, where files are stored, how data is encrypted, who holds the backup keys, who can sign in and how, who at the vendor can see your data, which sub-processors are involved, how breaches are handled, and how you leave. Then read the answers for specifics. A good answer names a mechanism and a number; a weak one names an adjective.

This is general information, not legal advice. Privacy law changes, and how it applies depends on your agency, your clients and where everyone is. Security questionnaires often reference laws such as the GDPR, UK GDPR, CCPA/CPRA, PIPEDA or Australia’s Privacy Act. For decisions about your own obligations, speak to a qualified adviser in the relevant country.

Why agencies need to ask#

When a client shares data with your agency, it expects you to protect it, and in many countries the law expects your client to check that you do. Your client can’t see inside your tools, so it asks you. You can only answer well if you have already asked your vendors. Doing it before you sign up to a tool is much easier than after two years of client data is inside it.

Our guides to GDPR for agencies and US state privacy laws explain where these duties come from.

The template: nine areas, the questions that matter#

Vendor security questionnaire template for agencies
AreaAskA good answer sounds likeRed flag
SeparationIs our data in a database of its own, or in a shared one with other customers?“Each customer has a separate database”, or a clear description of how shared data is isolated“It’s all secure” with no mechanism
FilesWhere are our files physically stored, and can we choose?A named location, or storage in an account we ownFiles only on the vendor’s servers, with no bulk export
EncryptionHow is data encrypted in transit and at rest? How are connection keys stored?HTTPS with HSTS; named encryption for stored secrets“Bank-grade encryption” and nothing else
BackupsHow often, how long kept, encrypted with whose key, can we restore ourselves?Nightly, a stated retention, key custody explained, a restore pathNo stated retention, or restore only “on request”
Sign-inHow are passwords stored? What stops password guessing? Is there a second factor?One-way hashing; lockouts after failed attempts; codes or another second stepPasswords recoverable in plain text; no lockout
Sessions and accessCan we see signed-in devices and end sessions? Can we limit access by role?A device list with sign-out; role-based access; clients see only their own areaEveryone sees everything; no session control
Vendor accessWho at your company can see our data, and when?Only for support you request or where the law requires“Our team may review content to improve the product”
Sub-processors and contractsDo you have a DPA and a sub-processor list? How are changes announced?A published DPA and list, with notice of changesNo list, or “we don’t share that”
IncidentsHow and how fast will you tell us about a breach? Who do we report issues to?A stated notice commitment and a security contactNo contact and no commitment
ExitCan we export everything ourselves? When is our data deleted after we cancel?Self-serve full export; a stated deletion periodExport by support ticket only; silence on deletion

TipSend the questions in writing and ask for written answers. Keep them with the date. Vendors change; so should your records.

How to read the answers#

  • Mechanisms beat adjectives. “Five wrong passwords lock the account for 15 minutes” tells you something. “Robust protection” tells you nothing.
  • Limits are a good sign. A vendor that says what it can’t do (for example, that it can’t open backups encrypted with your key, but that its app does process your live data) is usually being straight with you.
  • Check certifications properly. If a vendor cites a security certification or an audit report, ask what systems it covers and when it was last assessed. A badge on a website is not the report.
  • Watch for “we may”. Clauses saying the vendor may use content to improve services or train models deserve a direct follow-up question.

Right-size your expectations#

A small vendor may not have every formal certification a large enterprise does, and a large vendor may give you less control over where your data sits. Weigh the whole picture: a smaller tool that keeps files in your own storage and lets you hold the backup key can reduce your exposure more than a certificate does. Match the depth of the review to the sensitivity of the data. A whiteboard tool with no client personal data needs a lighter check than the system that holds your client contracts.

How Crewqo answers the core questions#

Our Why Crewqo page has a seven-question check you can run against any tool. Here are our answers in short, with links to the detail.

  • Separate database? Yes. Every agency has its own database; see separate databases.
  • Where are files stored? In the storage you connect: Google Drive, OneDrive or SharePoint, Dropbox, any S3-compatible bucket, or your own server over WebDAV. No permanent copy on our servers; see files in your storage.
  • Backups? Nightly, encrypted, kept 30 days, with a copy in your storage. Turn on your backup key and we can’t open them; see backups.
  • Encryption? HTTPS everywhere with HSTS. Passwords hashed with bcrypt. Keys for connected tools encrypted with AES-256-GCM; see encryption.
  • Sign-in and sessions? Five wrong passwords lock an account for 15 minutes; a 6-digit email code on sign-in when email is set up; owners see every signed-in device and can end sessions; see sign-in and devices.
  • Who sees what? Access is given by area; clients only see their own portal; the AI assistant only receives what the person asking can see; see access.
  • Vendor access? Your live workspace runs on our servers, so the app can read it to show it to you. We don’t look at workspace contents unless you ask us to help or the law requires it.
  • Exit? Export everything yourself, any time. If you cancel, we delete your workspace and the backups we hold within 30 days.

Security issues can be reported to support@crewqo.com.

Your vendor review routine#

For every tool that holds client data

Frequently asked questions

Should we only use vendors with a security certification?

It depends on what your clients require and how sensitive the data is. Certifications are useful evidence, but ask what they cover and when they were last assessed, and weigh them alongside practical controls like data separation, key custody and export.

How often should we review our software vendors?

Once a year is a sensible default, plus whenever a vendor announces a major change such as new sub-processors, new ownership or new terms.

What if a vendor won’t answer?

Treat it as an answer. If the tool holds client personal data, consider whether you can defend it to a client. For low-risk tools with no client data, a lighter review may be enough.

Can we reuse vendor answers in our own client questionnaires?

Yes, and you should. Keep vendor answers, DPAs and settings screenshots in one dated library, and you can answer most client questions about your tools in minutes.

Written by the Crewqo team. Spotted something out of date? Tell us at hello@crewqo.com.

Founding offer · first 50 agencies

Claim one of 50 founding spots

Save 20% for as long as you stay, start with a 14-day free trial, and cancel any time.

14-day free trialNo card neededCancel any time