An alternative for that vendor is to request their policies - their information security policy, their Incident Response, etc. I realize these are not reviewed and tested by an audit firm, but it at least provides a record of what the vendor claims is ...
More