QuickTrust Security and Trust Information
Find QuickTrust's public privacy information and learn how to request scoped security evidence for your vendor evaluation.
Get a readiness snapshotStart with the service you are evaluating
A useful security review identifies the product, deployment, information involved, and the controls your organization needs to understand. QuickTrust can help route those questions to a scoped discussion rather than asking you to infer the answers from marketing language.
This page is a starting point for due diligence. It is not a certification badge, an audit report, or an attestation that every deployment has the same control configuration.
Public documents
- Privacy policy: information about the handling of personal information.
- Terms of service: the terms published for use of the service.
- Integration planning: evidence workflow areas and setup questions.
- Implementation responsibilities: how to discuss staffing and ownership.
Read these materials in the context of your proposed contract and deployment. Where an answer depends on an environment, agreement, or current operational record, request that detail directly.
Request a scoped security review
Use Contact to provide the service you are evaluating, your review deadline, and the topics that matter to your organization. Common topics include access control, data handling, supplier responsibilities, change management, incident response, and recovery planning.
Begin with questions rather than uploading credentials, sensitive production records, or regulated data. If supporting material is available and appropriate to share, agree the recipient, confidentiality terms, and delivery method before exchanging it.
Assess evidence in context
For each document or response, check the owner, date, applicable systems, and exclusions. An architecture description answers different questions from an independent assurance report. A policy describes a commitment; operating records show how it was carried out.
Ask explicitly about any certification, assessment, hosting, retention, or incident-response requirement your procurement process imposes. The availability and scope of supporting evidence should be confirmed rather than inferred from a framework page.
For help structuring your own review, use the audit evidence checklist and security questionnaire guidance.