How secure is it?

What SaaS companies need to publish

Procurement wants evidence, not adjectives. The question is really 'what can you show me'.

How customers actually ask it

The same intent arrives in wording your page probably does not use. All of these mean the same thing:

  • How secure is it?
  • are you SOC 2
  • do you encrypt data
  • penetration testing
  • security certifications

What a complete answer contains

For SaaS companies specifically, an answer is only complete when it covers all 5:

  1. 1

    Certifications you actually hold, with dates — and silence rather than implication where you hold none

  2. 2

    Encryption in transit and at rest, stated separately

  3. 3

    Whether SSO and enforced MFA are available, and on which plan

  4. 4

    Penetration testing cadence and whether a summary is shareable

  5. 5

    How to report a vulnerability

A worked example

Illustrative — not a real business

TLS 1.3 in transit, AES-256 at rest. SSO via SAML on the Best plan; MFA available on all plans and enforceable per workspace. Annual third-party penetration test with a summary available under NDA. Report vulnerabilities to security@example.com.

Which page should own it

Security page

What silence costs

Claiming certifications you do not hold is worse than having none. Stating precisely what you do have is what passes review.

More questions SaaS companies get

Related

Does your site answer this already?

Point RubyRep at your website and ask it this exact question. If it cannot answer, neither can your customers.

https://

Takes about a minute. No credit card.