Turn the security review into a software decision.
A checklist is only part of a third-party software decision. These guides show how to collect evidence, judge what it proves, document uncertainty, and reach a decision a reasonable reviewer can explain later.
Two ways software enters the business.
Sometimes you can inspect what will run. Sometimes you have to evaluate the organization operating it. The evidence changes, but the decision discipline should not.
Review source-readable software and vendors
Understand why readable code and vendor attestations answer different questions, and how both fit into a defensible approval process.
Read the guide → VENDOR REVIEWHow to evaluate a new vendor's security
A step-by-step method for scoping the use, reading evidence, testing claims, recording gaps, and making a conditional decision.
Read the guide →Use the evidence you have. Name what you do not.
SOC 2 vendor review checklist
Turn a long report into a focused review of scope, exceptions, controls, and suitability.
SOC 2How to review a SOC 2 report
Read the opinion, system boundaries, tests, exceptions, and complementary controls without mistaking attestation for approval.
SAASSaaS security assessment checklist
Cover identity, data protection, operations, resilience, evidence quality, and the business context that changes the answer.
EXTENSIONSBrowser extension security review checklist
Evaluate permissions, data access, network behavior, update paths, provenance, and code-level risks.
SUPPLY CHAINHow to evaluate an NPM package before adoption
Inspect provenance, maintainers, install scripts, dependencies, advisories, malware signals, and the published artifact.
SOURCE REVIEWSource-readable software approval checklist
Review behavior, authentication, data protection, injection risk, cryptography, configuration, dependencies, and licensing.
SCOPEVendor risk review vs. vulnerability scanning
Learn what each method can establish, what each misses, and why one cannot substitute for the other.
DECISION RECORDWhat a deployment decision report should contain
See how evidence, gaps, business context, conditions, ownership, and reassessment become an auditable decision.
METHODOLOGYA practical third-party security review methodology
A repeatable framework for moving from intake to evidence, analysis, decision, and follow-up.
See the evidence workflow in the product.
Explore sample source and vendor reports without creating an account.