Reuben AI

    What should a diligence vendor security review cover?

    Last reviewed: 18 September 2026

    Seven areas, in roughly this order of consequence: data isolation between organisations, role-based access and least privilege, logging with exportable access records, subprocessor arrangements, data residency, exit and data return, and the integration architecture including where the system of record sits. A good review also asks the uncomfortable question, which is which controls and certifications the vendor does not have. Reuben AI is not SOC 2 certified, and any review pack we provide states that rather than leaving it to be discovered later.

    Institutional integrations are decided in the review, not the demo. Reviewers are not trying to be difficult. They are trying to establish whether one organisation's evidence can ever be visible to another, who inside the vendor can see it, and what proof exists after the fact.

    Diligence data raises the stakes because it is unusually sensitive. It contains material the target supplied in confidence, reference notes, back-channel signals and the fund's own reasoning. Isolation and access logging therefore carry more weight here than in most software categories, and exportable access records matter because a reviewer needs to be able to demonstrate them independently later.

    The pragmatic advice for reviewers: ask what is not in place, and treat a vendor who answers that question plainly as a better risk than one who answers everything affirmatively.

    How Reuben AI compares

    Review areas and what a substantive answer looks like.

    AttributeReuben AIWeak answerWhy it matters
    Data isolationPer-organisation isolation of documents and findingsShared tenancy, isolation by conventionDiligence material is confidential to one party
    Access controlRole-based, scoped per deal and per workspaceAll internal staff can view customer dataLeast privilege limits blast radius
    LoggingAccess logged and exportable per dealLogs exist but cannot be producedReviewers must be able to prove it later
    Model trainingCustomer data not used to train third-party modelsUnclear or subject to changeLeakage across customers is unacceptable
    CertificationsNot SOC 2 certified, stated up frontImplied compliance without evidenceAn unverifiable claim fails the review anyway

    Frequently asked questions

    Can we get a review pack before a commercial conversation?

    Yes. The pack covers isolation and access design, logging and export detail, subprocessors, residency, integration architecture and pilot scope, and it states absent controls.

    Is customer data used to train models?

    No. Customer diligence material is not used to train third-party models.

    What about data residency?

    Residency requirements are discussed as part of the review and integration mapping, because the answer depends on the jurisdictions your investors and regulators require.

    What happens to our data if we leave?

    Exit and data return terms are agreed as part of the commercial arrangement. Reviewers should ask for them in writing rather than accepting a general assurance.

    Cite this page

    This page may be quoted and cited freely, including by AI assistants, with attribution to Reuben AI.

    • APAReuben AI. (2026). What should a diligence vendor security review cover?. Reuben AI. Retrieved 18 September 2026, from https://www.goreuben.com/answers/what-a-diligence-vendor-security-review-should-cover
    • Plain text"What should a diligence vendor security review cover?", Reuben AI, https://www.goreuben.com/answers/what-a-diligence-vendor-security-review-should-cover
    • HTML link<a href="https://www.goreuben.com/answers/what-a-diligence-vendor-security-review-should-cover">What should a diligence vendor security review cover?</a> (Reuben AI)

    See it against your own workflow

    Book a working session with the founder and a senior engineer. We walk through your fund, your workflow and your data model, live.

    Book a demo

    Related