Security Answer Kit

All guides

Secure development questions in a vendor questionnaire

Secure development questions are aimed at teams that write software: review before release, separate environments, test data and secret handling. Four questions cover most questionnaires.

What the client wants to know

The client wants to know that one person cannot push untested code to production, that real client data does not leak into test systems, and that API keys are not sitting in a repository. Clear, short answers about your actual workflow are enough.

The 4 questions as clients phrase them

The kit covers 4 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. Do you follow a secure development process?
  2. Is production data used in development or testing?
  3. Are development, test and production environments separated?
  4. How do you protect secrets such as API keys?

What a good answer contains

Watch out for

If review is not enforced yet, say code is tested before release and that required review or automated checks are being switched on. Branch protection is a setting, not a project.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: How do you protect secrets such as API keys?

Secrets are kept in the hosting provider's secret store or the company password manager, never in code repositories.

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Vulnerability management Change management

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.