Secure development questions in a vendor questionnaire
Secure development questions are aimed at teams that write software: review before release, separate environments, test data and secret handling. Four questions cover most questionnaires.
What the client wants to know
The client wants to know that one person cannot push untested code to production, that real client data does not leak into test systems, and that API keys are not sitting in a repository. Clear, short answers about your actual workflow are enough.
The 4 questions as clients phrase them
The kit covers 4 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Do you follow a secure development process?
- Is production data used in development or testing?
- Are development, test and production environments separated?
- How do you protect secrets such as API keys?
What a good answer contains
- Process: code is reviewed by a second person or by automated checks before release, the main branch is protected, secrets are not stored in code.
- Environments: production is separate from development and test, with its own credentials, and only named people can deploy to production.
- Test data: development and testing use test data. If production data is ever needed to fix a problem, it is limited to what is needed and removed afterwards.
- Secrets: kept in the hosting provider's secret store or the password manager, never in code repositories, and rotated when someone with access leaves.
Watch out for
If review is not enforced yet, say code is tested before release and that required review or automated checks are being switched on. Branch protection is a setting, not a project.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Development: Code is reviewed by a second person or by automated checks before release. If not yet: Protect the main branch and require a review or passing checks before merge.
- Access: All staff use a password manager. Passwords are not shared in chat or documents. If not yet: Roll out a password manager for everyone and move shared logins into shared vaults.
Example: how a prepared answer opens
Question: How do you protect secrets such as API keys?
Secrets are kept in the hosting provider's secret store or the company password manager, never in code repositories.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.