Security and compliance: Ask for current SOC 2 Type II or ISO 27001; if not available, require a roadmap and interim controls. Data residency should match regulatory exposure; EU PII may require EU data centers and SCCs. Breach notification within 72 hours is standard; for regulated data, 24 hours may be warranted. Require annual pen […]