Deskpro Vendor Security Requirements
Last Updated: 4 March 2026
These Vendor Security Requirements (“Deskpro Security Requirements”) apply only where incorporated by reference into a written agreement between Deskpro and a supplier, vendor, subcontractor, or other third party (“Vendor”).
1. Introduction
Deskpro requires Vendors that access, store, transmit, support, or otherwise interact with Deskpro systems or Deskpro information to maintain appropriate administrative, technical, and organisational security controls.
These Security Requirements are intended to define minimum expectations. Vendors may implement equivalent or alternative controls provided they achieve a comparable security outcome.
2. Scope and Applicability
These Security Requirements apply to Vendors and Vendor Personnel who access, store, transmit, support, or otherwise interact with Deskpro systems or Deskpro information, where incorporated into a written agreement with Deskpro.
Where Vendor is an individual, or where Vendor Personnel operate within Deskpro-managed systems and environments under Deskpro supervision, compliance with Deskpro-issued policies, device controls, access controls, and training requirements will satisfy the applicable portions of these Security Requirements.
Entity-level governance and control requirements apply only to Vendors providing organisational services involving independent systems, infrastructure, hosted environments, or facilities outside Deskpro’s direct management.
3. Governance, Risk, and Compliance
Vendor must maintain a documented information security program that is reviewed periodically and supported by management oversight. The program must be aligned to recognised frameworks such as ISO/IEC 27001, SOC 2, or equivalent.
Vendor must designate an individual or function responsible for oversight of the information security program.
Vendor must maintain a risk management process to identify, assess, treat, and monitor security risks relevant to the services provided to Deskpro.
Vendor must ensure its security policies, procedures, and controls are documented, implemented, and reviewed on a periodic basis.
Vendor must implement, maintain, and periodically test administrative, technical, and organisational controls to ensure the security and integrity of systems used to access, store, process, or transmit Deskpro information.
4. Personnel Security
Vendor must ensure that personnel who provide services to Deskpro (“Vendor Personnel”) are:
- contractually bound by confidentiality and information security obligations no less protective than those required under the parties’ agreement; and
- trained on security and privacy responsibilities relevant to their role.
Vendor must perform appropriate background checks on Vendor Personnel where legally permissible and proportionate to the role and access.
Vendor represents and warrants that it shall not assign any individual to perform services for Deskpro who has been convicted of, pled guilty or no contest to, or participated in a pre-trial diversion program for any felony, or for multiple misdemeanor offences, involving dishonesty, fraud, theft, embezzlement, money laundering, breach of trust, controlled substances trafficking, or criminal conspiracy.
Vendor must ensure Vendor Personnel act only in accordance with Deskpro’s documented instructions and only for authorised purposes.
5. Access Control and Authentication
Vendor must implement access control policies and procedures that enforce:
- least privilege;
- role-based access controls;
- segregation of duties where appropriate; and
- removal of access upon role change or termination.
Vendor must ensure:
- unique user accounts are used (no shared accounts for human users);
- multi-factor authentication (MFA) is required for privileged access and remote access;
- passwords and secrets are protected and not shared; and
- access is logged where appropriate.
Where Deskpro requires Vendor Personnel to access Deskpro systems, Vendor must comply with Deskpro’s access and identity requirements, including the use of Deskpro-managed accounts where required.
6. Device, Endpoint, and Remote Working Security
Where Vendor Personnel access Deskpro systems or Deskpro information, Vendor must ensure such access occurs only through secure, managed, and approved devices and environments.
Vendor must implement controls appropriate to the services and risk profile, including:
- endpoint malware protection;
- secure configuration baselines;
- timely security patching;
- device encryption where appropriate;
- secure remote working practices; and
- physical safeguards to prevent loss, theft, or unauthorised access.
Where required by Deskpro, Vendor Personnel must access Deskpro systems and information exclusively through Deskpro-issued and Deskpro-managed devices, systems, or environments.
Vendor must not permit the use of personal devices, unmanaged systems, or unauthorised tools where Deskpro has specified that Deskpro-managed equipment is mandatory.
Vendor must ensure that systems and infrastructure used to provide services to Deskpro are housed in physically secure premises with facility access controls and environmental safeguards (including fire detection and suppression where appropriate), proportionate to the nature and sensitivity of the services.
7. Data Protection and Encryption
Vendor must implement appropriate safeguards to protect Deskpro information from unauthorised access, disclosure, alteration, destruction, or loss.
Vendor must ensure:
- encryption is used to protect Deskpro information in transit using industry-standard protocols;
- encryption is used to protect Deskpro information at rest where appropriate to the risk profile and sensitivity of the data;
- cryptographic keys are generated, stored, rotated, and retired securely throughout their lifecycle; and
- encryption algorithms and key lengths are aligned to recognised industry standards or equivalent security practices.
Vendor must securely delete, destroy, or sanitise storage media containing Deskpro information before disposal or reuse, using industry-standard methods appropriate to the media type.
Vendor must comply with Deskpro’s detailed requirements relating to data protection, available at:
8. Secure Configuration and Network Security
Vendor must maintain secure baseline configurations for systems used to provide services to Deskpro, aligned to industry best practices. Vendor must implement appropriate network security controls, including (where relevant):
- network segmentation;
- firewalling and access restrictions;
- protections against common web application attacks; and
- controls to detect and prevent unauthorised network access.
9. Logging, Monitoring, and Detection
Vendor must maintain appropriate security monitoring to detect suspicious activity affecting systems used to provide services to Deskpro. Vendor must maintain security logs with an appropriate retention period and protect log integrity.
10. Vulnerability Management and Penetration Testing
Vendor must implement, maintain, and enforce a documented vulnerability management program covering all systems, infrastructure, applications, environments, and software used to provide services to Deskpro.
At a minimum, Vendor must:
- actively monitor reputable industry sources for security alerts and vulnerabilities, including the NIST National Vulnerability Database and applicable vendor security bulletins;
- conduct vulnerability scanning at least monthly, including:
- authenticated and unauthenticated scans of internal systems used to provide services to Deskpro; and
- unauthenticated scans of external-facing systems used to provide services to Deskpro;
- prioritise vulnerabilities using the current version of the Common Vulnerability Scoring System (CVSS) or an equivalent industry-standard methodology;
- track remediation activities in a documented system; and
- validate remediation prior to closure.
10.1 Critical Vulnerabilities (CVSS 9.0 or Higher)
Where Vendor identifies a vulnerability classified as CVSS 9.0 or higher (or equivalent critical severity) affecting any environment used to provide services to Deskpro (“Critical Vulnerability”), Vendor must:
- notify Deskpro within 48 hours of discovery;
- provide a written description of the vulnerability and its potential impact to Deskpro within 48 hours of discovery;
- provide a written and detailed remediation plan within 72 business hours of discovery; and
- provide written confirmation and substantiation promptly following remediation.
If Deskpro inquires about the impact of a known Critical Vulnerability, Vendor must respond in accordance with the timelines above.
10.2 Zero-Day Vulnerabilities
Where Vendor provides software (including SaaS, hosted services, software development services, or commercial off-the-shelf software), Vendor must respond to Deskpro inquiries regarding Critical Vulnerabilities or vulnerabilities for which no mitigation exists (“Zero-Day Vulnerabilities”) within 24 hours of receiving such inquiry.
10.3 Penetration Testing
Vendor must conduct penetration testing or equivalent security assessments of in-scope systems used to provide services to Deskpro at least annually, and following material changes to systems or architecture.
Penetration testing must:
- include both automated and manual testing methodologies;
- align with recognised industry standards such as CREST; and
- include testing for commonly exploited vulnerabilities, including those identified in the OWASP Top 10, CWE Top Weaknesses, or equivalent recognised industry guidance.
Vendor must provide evidence of such testing and remediation of identified critical or high-risk findings upon request.
11. Secure Development and Software Supply Chain
Where Vendor develops software, provides software development services, provides hosted or SaaS services, or supplies software used by Deskpro, Vendor must implement and maintain a secure software development lifecycle (“SDLC”) aligned to recognised industry standards (such as ISO/IEC 27001, SOC 2, or equivalent).
Vendor’s SDLC must include, at a minimum:
- documented security requirements integrated into design and development processes;
- threat modelling and security design reviews for new systems, major releases, and material architectural changes;
- static application security testing (SAST) across the full codebase;
- dynamic application security testing (DAST) for web-based applications and APIs;
- manual and automated application penetration testing using recognised industry methodologies;
- security review of open-source and third-party components, including:
- vulnerability evaluation;
- inventory management;
- appropriate licensing validation; and
- documented vulnerability management processes providing for timely remediation of identified security weaknesses.
Testing must evaluate, at a minimum, vulnerabilities identified in the then-current versions of widely recognised industry resources, including OWASP Top 10 and Common Weakness Enumeration (CWE) guidance, or equivalent industry standards.
11.1 Annual Substantiation
Vendor must be able to substantiate, at least annually and prior to implementing major releases affecting Deskpro services, that the above application security controls are documented, implemented, and enforced.
Upon request, Vendor must provide:
- summaries of testing performed;
- remediation status of identified critical or high-risk findings; and
- evidence demonstrating closure of material findings.
If Vendor cannot substantiate that the required controls are documented, implemented, and enforced, Vendor must engage a qualified independent security testing provider and provide the results of such testing to Deskpro prior to production release.
Vendor must remediate critical and high-risk vulnerabilities prior to production deployment unless an alternative mitigation has been formally documented and approved by Deskpro.
12. Incident Management and Notification
Vendor must maintain documented incident detection, response, escalation, containment, remediation, and recovery procedures covering systems, environments, and services used to provide services to Deskpro.
Vendor must ensure that such procedures include defined roles and responsibilities, internal escalation processes, evidence preservation procedures, and communication protocols.
12.1 Notification Obligations
Vendor must notify Deskpro at security@deskpro.com :
- within four (4) hours of senior management within Vendor’s (or its subcontractors’) cybersecurity, privacy, or technology organisations being notified of a suspected Security Incident affecting Deskpro; and
- within four (4) hours of confirmation of a Security Incident.
12.2 Security Incident Definition
A “Security Incident” means any event that results in:
- unauthorised access to, disclosure of, alteration of, or destruction of Deskpro information;
- unauthorised access to or compromise of systems that store, process, or transmit Deskpro information;
- loss of integrity of Deskpro information;
- unavailability or material degradation of services provided to Deskpro; or
- a violation, or imminent threat of violation, of Vendor security policies or standard security practices that affects systems used to process, store, or transmit Deskpro information.
12.3 Required Information
Notification must include, to the extent known at the time:
- a description of the nature and cause of the incident;
- whether Deskpro information or systems are affected;
- the scope and impact of the incident;
- corrective actions taken or planned; and
- steps taken to prevent recurrence.
Vendor must:
- take immediate steps to contain and remediate the incident;
- preserve relevant logs, records, and evidence; and
- cooperate fully with Deskpro’s investigation, remediation, regulatory response, and customer communications.
13. Business Continuity and Resilience
Vendor must implement, maintain, and enforce documented business continuity and disaster recovery (“BCDR”) plans covering services provided to Deskpro.
Such plans must include, at a minimum:
- continuity of services with no or minimal interruption;
- recovery of Deskpro Information;
- recovery of systems, infrastructure, and telecommunications required to deliver services;
- procedures for replacement of critical personnel where necessary; and
- defined recovery time objectives (RTO) and recovery point objectives (RPO) appropriate to the services provided.
Vendor must test its BCDR plans at least annually, and following material changes to relevant systems or infrastructure.
Upon request, Vendor must provide Deskpro with:
- summaries of BCDR testing performed;
- identified deficiencies; and
- remediation actions taken.
Where services are designated by Deskpro as critical, Vendor must comply with any additional resilience or recovery requirements specified by Deskpro.
14. Subcontractors and Third Parties
Vendor must not permit any subcontractor, affiliate, agent, or other third party to access, process, store, transmit, or support Deskpro systems or Deskpro information in connection with the services unless authorised under the parties’ agreement and in accordance with this Section.
Vendor must ensure that each approved subcontractor is bound by written obligations that are no less protective than these Security Requirements for the relevant scope, and that require the subcontractor to comply with all Vendor obligations applicable to the subcontracted services. Vendor remains fully responsible for the acts and omissions of all subcontractors.
14.1 Due Diligence
Before engaging any subcontractor that will access, process, store, transmit, support, or otherwise interact with Deskpro systems or Deskpro information, Vendor must complete documented due diligence that covers, at a minimum:
- information security controls and security governance relevant to the subcontracted scope;
- operational resilience, business continuity, and disaster recovery capability relevant to the services;
- financial and operational stability relevant to the subcontracted scope; and
- compliance capability for applicable laws, regulatory requirements, and contractual obligations relevant to the services.
Vendor must retain due diligence records and provide evidence of completion upon request.
14.2 Subcontracting Approval
Vendor must not subcontract any Deskpro-related obligation to a third party that will:
- access, process, or otherwise have access to Deskpro information;
- access Deskpro systems;
- provide a material component of the services;
- provide customer-facing or public-facing functionality related to Deskpro services; or
unless Vendor has first:
- completed the due diligence requirements in Section 14.1;
- entered into the written flow-down agreement required by this Section; and
- provided Deskpro with prior written notice identifying the proposed subcontractor and the nature and scope of its involvement.
14.3 Notice and Objection
Vendor must provide Deskpro with at least 30 days’ prior written notice before engaging any new subcontractor that will access, process, store, transmit, support, or otherwise interact with Deskpro systems or Deskpro information.
Deskpro may object to the proposed subcontractor where Deskpro determines that the subcontractor presents a material security, privacy, regulatory, operational, or compliance risk.
Where Deskpro must flow down customer or regulatory requirements (including for regulated customers), Deskpro may require an extended review period of up to 60 days prior to engagement.
If Deskpro objects, Vendor must not engage the subcontractor for Deskpro-related services unless and until the concern is resolved to Deskpro’s satisfaction.
14.4 Audit and Regulatory Flow-Down
Vendor must ensure that subcontractors supporting the services provide Deskpro with equivalent audit, information, and access rights for the relevant scope, including cooperation needed for Deskpro to respond to audits, regulatory/supervisory requests, and customer due diligence requests relating to the services.
15. Evidence, Assurance, and Audit Support
Vendor must provide Deskpro, upon request and upon notice, with access to information, documentation, and personnel necessary to validate Vendor’s compliance with these Security Requirements and to enable Deskpro to meet its contractual, regulatory, audit, and customer obligations.
15.1 Independent Security Assurance
Where Vendor provides hosted services, software services, managed services, infrastructure services, or otherwise processes, stores, transmits, or supports Deskpro information outside Deskpro-controlled environments, Vendor must maintain independent third-party security assurance at least annually for the systems, environments, and locations in-scope for the services, consisting of one of the following:
- a SOC 2 Type II report; or
- an ISO/IEC 27001 certification (including the current certificate and the most recent surveillance/recertification audit report summary); or
- another industry-recognised independent assessment report that Deskpro confirms in writing is acceptable for the relevant scope.
Vendor must make available to Deskpro the relevant sections or an executive summary sufficient to demonstrate the scope and results for the services, subject to appropriate confidentiality protections.
If Vendor does not have the required independent assurance, Vendor must promptly notify Deskpro. Deskpro may (at its discretion) permit an alternative assurance approach for a limited period, which may include an independent assessment commissioned by Vendor, targeted testing, or additional evidence and controls agreed in writing.
15.2 Scope of Audit Rights
Vendor must cooperate with technical, financial, and operational audits and assessments relating to services provided to Deskpro. Such cooperation may include:
- security assessments;
- disaster recovery testing reviews;
- vulnerability management reviews;
- review of Vendor control environments;
- review of facilities and service locations used to provide services to Deskpro;
- review of policies, procedures, and control documentation; and
- written attestations and certifications.
Non-regulatory audits will not occur more than once per calendar year per service scope unless:
- a prior audit identified material findings;
- Vendor is in, or alleged to be in, material breach of its obligations;
- a significant Security Incident has occurred; or
- an emergency situation requires additional review.
15.3 Regulatory and Customer Cooperation
Where Deskpro must respond to audit, regulatory, supervisory, or information requests from its customers (including regulated financial institutions) or regulators relating to services performed by Vendor, Vendor must:
- provide timely and complete information;
- cooperate with competent regulatory or supervisory authorities where legally permissible;
- provide documentation, written explanations, and supporting evidence; and
- support interviews or information requests relating to the services provided.
Vendor must ensure that any subcontractors supporting the services grant Deskpro, its customers, and relevant regulators equivalent audit, information, and access rights for the applicable scope.
15.4 Remediation
If any audit, assessment, or review identifies material deficiencies, Vendor must:
- implement a remediation plan agreed with Deskpro; and
- provide status updates upon request until remediation is complete.
Failure to provide cooperation or remediation may constitute a material breach of the parties’ agreement.
16. Updates to These Requirements
Deskpro may update these Security Requirements from time to time by publishing an updated version at this URL.
17. Enforcement
Failure to comply with these Security Requirements may constitute a material breach of the parties’ agreement and may result in remediation requirements, suspension of access, or termination.