Home/Blog/Vendor security checklist
SecurityAug 26, 2026·7 min read·The ExcelSurge team

Vendor Security Questions Finance Teams Should Ask

A practical due-diligence checklist for any tool that touches your financial models, where data is processed, what's stored, what's transmitted, and what to get in writing.

Every tool you add to your modeling stack is a tool your compliance team may one day have to account for. Before you install something that touches confidential financial data, it's worth running a short due-diligence pass. You don't need a formal security program to do it. You need the right questions.

Here's a practical checklist. It works for an Excel add-in, a PowerPoint tool, or any desktop software that opens your files. Save it, and paste the relevant parts into your next vendor conversation.

Where is my data processed?

The foundational question. Ask whether the tool processes your files locally on your machine or on the vendor's servers. For confidential models, local processing means your data never leaves your endpoint to do the work. If it's cloud-processed, everything below matters much more.

What, exactly, is transmitted?

"We take security seriously" is not an answer. Ask for specifics: when the tool runs, is any part of the file's contents sent anywhere? Some tools transmit nothing but a license check. Others send telemetry. Others upload the whole document. Get the precise list of what leaves the machine and when.

What is stored, where, and for how long?

If anything is transmitted, ask what's retained. Is your file stored server-side, even temporarily? For how long? Is it encrypted at rest? A vendor that stores nothing has a much smaller attack surface than one holding copies of every model its users touch.

Is data encrypted in transit?

Any network call the tool makes: license checks included, should be over TLS/HTTPS. This is table stakes in 2026, but confirm it. There should be no unencrypted channel, and ideally no channel that carries your data at all.

What telemetry is collected, and can I turn it off?

Usage analytics are common and often harmless. What matters is disclosure and control: is telemetry on by default or opt-in? Does it ever include your actual content, cell values, file names, or only anonymous feature counts? Can you disable it entirely? A tool that sends anonymous, opt-in usage data that never touches your models is very different from one that quietly phones home with your file names.

Does it work offline?

A quick, revealing test. Disconnect from the network and run the core feature. If it still works, the processing is genuinely local. If it fails, part of the work is happening somewhere else, worth understanding where.

What security practices and certifications do you follow?

Ask what standards the vendor builds to, access controls, encryption, least-privilege, logging. Frameworks like SOC 2 and ISO 27001 describe these practices. Note the difference between a vendor that follows the practices and one that holds a completed third-party certification; both are legitimate answers, but they're not the same claim, and a serious vendor will tell you which one they mean.

Can I get the important answers in writing?

For anything that matters to your compliance team, get it documented, a security page, an email, a completed questionnaire. "Someone told me on a call" doesn't hold up later. A vendor confident in its security posture will put it in writing without friction.

How ExcelSurge answers these

Since we build for this audience, we try to answer these before you ask. ExcelSurge processes everything locally inside Excel; no workbook data is transmitted or stored; the only network calls are a license check and optional, off-by-default anonymous usage stats that never include your data; and everything runs over HTTPS. We lay it out row by row on our security page so you can drop it straight into a review.

Whatever you end up choosing, run the checklist. The five minutes it takes is a lot cheaper than explaining to compliance why a confidential model ended up on a server nobody vetted.

Answers ready for your security review

ExcelSurge is local-first: nothing in your workbook is uploaded or stored. See exactly what does and doesn't leave your machine on our security page. 14-day free trial · $20/month.

Download free