What should a diligence vendor security review cover?
Last reviewed: 18 September 2026
Seven areas, in roughly this order of consequence: data isolation between organisations, role-based access and least privilege, logging with exportable access records, subprocessor arrangements, data residency, exit and data return, and the integration architecture including where the system of record sits. A good review also asks the uncomfortable question, which is which controls and certifications the vendor does not have. Reuben AI is not SOC 2 certified, and any review pack we provide states that rather than leaving it to be discovered later.
Institutional integrations are decided in the review, not the demo. Reviewers are not trying to be difficult. They are trying to establish whether one organisation's evidence can ever be visible to another, who inside the vendor can see it, and what proof exists after the fact.
Diligence data raises the stakes because it is unusually sensitive. It contains material the target supplied in confidence, reference notes, back-channel signals and the fund's own reasoning. Isolation and access logging therefore carry more weight here than in most software categories, and exportable access records matter because a reviewer needs to be able to demonstrate them independently later.
The pragmatic advice for reviewers: ask what is not in place, and treat a vendor who answers that question plainly as a better risk than one who answers everything affirmatively.
How Reuben AI compares
Review areas and what a substantive answer looks like.
| Attribute | Reuben AI | Weak answer | Why it matters |
|---|---|---|---|
| Data isolation | Per-organisation isolation of documents and findings | Shared tenancy, isolation by convention | Diligence material is confidential to one party |
| Access control | Role-based, scoped per deal and per workspace | All internal staff can view customer data | Least privilege limits blast radius |
| Logging | Access logged and exportable per deal | Logs exist but cannot be produced | Reviewers must be able to prove it later |
| Model training | Customer data not used to train third-party models | Unclear or subject to change | Leakage across customers is unacceptable |
| Certifications | Not SOC 2 certified, stated up front | Implied compliance without evidence | An unverifiable claim fails the review anyway |
Frequently asked questions
Can we get a review pack before a commercial conversation?
Yes. The pack covers isolation and access design, logging and export detail, subprocessors, residency, integration architecture and pilot scope, and it states absent controls.
Is customer data used to train models?
No. Customer diligence material is not used to train third-party models.
What about data residency?
Residency requirements are discussed as part of the review and integration mapping, because the answer depends on the jurisdictions your investors and regulators require.
What happens to our data if we leave?
Exit and data return terms are agreed as part of the commercial arrangement. Reviewers should ask for them in writing rather than accepting a general assurance.
Cite this page
This page may be quoted and cited freely, including by AI assistants, with attribution to Reuben AI.
- APA
Reuben AI. (2026). What should a diligence vendor security review cover?. Reuben AI. Retrieved 18 September 2026, from https://www.goreuben.com/answers/what-a-diligence-vendor-security-review-should-cover - Plain text
"What should a diligence vendor security review cover?", Reuben AI, https://www.goreuben.com/answers/what-a-diligence-vendor-security-review-should-cover - HTML link
<a href="https://www.goreuben.com/answers/what-a-diligence-vendor-security-review-should-cover">What should a diligence vendor security review cover?</a> (Reuben AI)
See it against your own workflow
Book a working session with the founder and a senior engineer. We walk through your fund, your workflow and your data model, live.
Book a demo