← All buyer's guides

A business owner's software security checklist

A plain-language security checklist for business software: identity, permissions, approvals, audit history, backups, exports and supplier evidence.

A secured business ledger with access cards and a visible audit trail.
The short answer

Security is operational control, not a badge. Check whether every person has their own identity, access is limited by role and site, important actions require approval, changes remain traceable, backups are recoverable and your data can leave with you.

01

Give every person their own identity

Shared accounts make a cheap licence expensive. When several people use one login, the business cannot prove who changed a price, approved a refund or exported customer data. Every employee and service account should be individually identifiable.

Ask how access is created, changed and removed. A leaver process matters as much as the login screen. Managers should be able to remove access promptly without deleting the history of work already done.

02

Limit access by role, site and value

A cashier, stock controller, payroll officer and owner need different views and actions. Permissions should follow the job and, where relevant, the branch. Sensitive actions can also use value limits so routine work stays fast while unusual risk needs approval.

Test permissions in the demo. Sign in as a normal user and attempt to view payroll, change a price, issue a large refund and open another branch's records. A policy document is not enough if the product does not enforce it.

03

Preserve corrections instead of erasing history

Business records change. The control is whether a correction keeps the original event, the new value, who changed it, when and why. Ask the supplier to trace one edited transaction from the report back to its source.

Approvals should live beside the work they control. A WhatsApp message that says ‘approved’ but is disconnected from the payment or adjustment leaves finance to rebuild the evidence later.

An audit trail only helps when a manager can follow a number back to the person and reason behind it.
04

Ask for backup and restore evidence

‘We take backups’ answers only half the question. Ask how often, where copies are kept, who can access them, how long they are retained and when a restore was last tested. A backup that has never been restored is an assumption.

Agree the recovery expectations that matter to your operation: how much recent work could be lost and how long the business can operate without the central service. Those answers may differ by plan or deployment, so get them in the contract where they matter.

05

Confirm that your data can leave with you

The exit question is part of security. Ask what you can export, in which format, who is allowed to export it and what happens to retained copies after the relationship ends. Core business records should not become a hostage to the application.

For enterprise or private deployments, document the responsibilities on both sides: updates, monitoring, backups, identity, incident contact and the boundary between supplier and customer infrastructure.

06

Distinguish evidence from marketing claims

A certification, approval or uptime number should be current, scoped to the service you are buying and available for review under appropriate confidentiality. If a supplier has not established a claim, the honest answer is to say so and explain the controls that do exist.

Keep a short decision record with the evidence reviewed, remaining risks, contract commitments and the person accepting each risk. That is more useful than collecting badges without understanding what they cover.

Take this checklist into the demo

  • Individual identities and prompt leaver removal
  • Role, site and value-based access
  • Approvals tied to the controlled transaction
  • Traceable corrections and exports
  • Backup schedule and restore evidence
  • Data export and exit process
  • Contracted responsibilities and incident contacts
Questions buyers ask

Straight answers before you commit.

What security questions should I ask a software vendor?

Ask how identities and leavers are managed, how access is limited, whether changes remain traceable, how backups are restored, how incidents are handled and how your data is exported at exit.

Is an audit trail the same as a backup?

No. An audit trail explains changes inside the business record. A backup is a recoverable copy used after loss or corruption. A responsible system needs both controls for different risks.

Does Corelith claim security certifications?

Corelith does not publish certifications or regulatory approvals that have not been formally established for the service a customer buys. Enterprise reviews document the controls and commitments that actually apply.

Continue the decision

See the product evidence.

Take the checklist into the room.

Work through it with our engineers on a call, question by question. Anything we cannot show you running, we will say so rather than describe it.