# Vendor Security Testing Questionnaire

1. Who will actually perform the assessment and what is their relevant experience?
2. How do you combine automated testing with manual validation?
3. How are false positives removed?
4. Do you safely demonstrate exploitability and attack paths?
5. Can we review a sanitized sample report?
6. What does the executive summary contain?
7. What technical reproduction detail is provided?
8. Is a live debrief included?
9. How does retesting work?
10. How is assessment data protected and retained?
