Aaron Bedra (updated annually, publicly available) While addressed to CTO practitioners, this checklist provides a useful framework for the technical due diligence questions that compliance teams should ask of SaaS vendors, covering data security architecture, incident response, and sub-processor ma