SSO/MFA enforcement, least-privilege role design, offboarding SLAs, and access reviews — ask for the process in writing and a redacted example of it operating.
Secrets management (vault, not .env files in chat), dependency scanning, code review requirements, and separation of client environments — shift-left evidence, not posters.
Managed/encrypted devices, no production data on laptops, masked test data — the laptop in the café is the breach vector nobody models.
Incident disclosure history and how they handled it, certifications if claimed (verify), and contractual security obligations with audit rights — trust, structured.
Skipping the discipline this article describes until an incident, audit, or stalled project forces it — every practice above is cheaper adopted early than retrofitted under pressure.
Let's discuss how we can help you with vetting security practices.