Vendor-neutral guide · 8 min read
Security questions to ask any remote access vendor before you buy
Written by the 247connect Marketing Team
Shape of the topic
In short
Buying a remote access or remote support tool is a security decision as much as an operational one, since the product will sit on a direct path into your devices and data. Marketing pages rarely give a clean answer to the questions that actually matter, so this guide sets out the questions worth putting to any vendor directly, organised by theme, along with why each one is worth asking rather than assuming.
Key takeaways
- Encryption, authentication, logging, hosting and support are the five areas worth probing with any remote access vendor.
- Ask for specifics, encryption standard, log retention period, MFA options, rather than accepting general reassurance.
- Where a vendor cannot answer a question directly, that gap is itself useful information.
- Questions about data residency and subprocessors matter as much as questions about the product's own security features.
- Named accounts, session logs and encrypted connections should be treated as baseline expectations, not premium extras.
- Confirm any regulatory implications of your answers with your own compliance adviser, since obligations vary by sector.
Encryption and how sessions are protected
Ask what encryption standard protects a session in transit, and whether that applies to screen data, keystrokes and file transfers equally. AES-256 is a widely used, well-regarded standard, and a vendor should be able to state clearly which algorithm and key length they use rather than answering only with a general claim of encryption. Ask too whether encryption keys are managed by the vendor or can be controlled by the customer, since that affects who could theoretically access session content.
It is also worth asking whether the connection is end-to-end encrypted or whether it passes through a relay that can, even briefly, see unencrypted content. Most cloud-brokered remote access tools use a relay for connectivity reasons, which is not inherently a problem, but you should know whether that relay point ever has access to plaintext data.
- What encryption standard and key length is used for session traffic
- Does encryption cover file transfer as well as screen and input data
- Does any relay point in the connection path ever see unencrypted content
Authentication and account management
Ask whether the product supports named individual accounts per operator, rather than a shared login for a whole support team, since shared accounts make it impossible to attribute a session to a specific person after the fact. Ask whether multi-factor authentication is available, whether it can be enforced organisation-wide rather than left optional per user, and which MFA methods are supported.
It is also worth asking how quickly an account can be disabled, and whether that takes effect immediately or only at the next login, since a delay here directly affects how fast you can cut off a departing employee or a compromised credential.
- Are named individual accounts supported and enforced, not just available
- Can multi-factor authentication be mandated for every user, not left optional
- How quickly does disabling an account actually take effect
Logging, audit and retention
Ask exactly what a session log records: operator identity, target device, start and end time, and whether actions within the session, such as file transfers, are separately logged. Ask how long logs are retained by default, whether that period can be configured, and in what format logs can be exported for your own retention or audit purposes.
Ask, too, whether session content itself can be recorded as video, separate from metadata logging, and if so, who can access those recordings and how they are stored. A vendor that can answer these questions precisely, with figures rather than general assurances, is giving you something you can actually put in your own compliance documentation.
- What fields does a session log capture, and can it be exported
- What is the default log retention period, and is it configurable
- Is full session recording available, and who can access recorded content
Hosting, data residency and subprocessors
Ask where session data and metadata are actually processed and stored, and whether that location is fixed or can vary depending on how the service routes traffic. If your organisation has obligations around keeping data within the UK or the European Economic Area, this answer matters directly rather than being a background detail.
Ask which subprocessors the vendor uses, for example a cloud hosting provider, and whether the vendor can provide a data processing agreement that names them. A vendor unable to answer where data goes or who else touches it is not necessarily acting in bad faith, but it does mean you are buying without a complete picture.
Support, pricing and what happens if you leave
Ask how the vendor prices the product, whether that pricing is fixed and predictable or based on variable usage that could shift unexpectedly, and what happens to your access, your logs and any recorded sessions if you cancel. A vendor offering fixed, predictable pricing, of the kind organisations such as 247connect use, makes budgeting more straightforward than a variable per-session or per-minute model, though the right pricing model depends on your own usage pattern.
Finally, ask what security testing the vendor undertakes on its own product, such as penetration testing or vulnerability scanning, and how often. This will not always be information a vendor shares in full detail, but a vendor with a mature security practice should be able to describe its approach at a reasonable level even without disclosing every technical finding.
Best-practice checklist
1. Get the encryption standard in writing
Ask the vendor to confirm, in writing, the encryption algorithm and key length used for session traffic and file transfers.
2. Confirm named accounts and enforceable MFA
Check that individual named accounts are supported and that multi-factor authentication can be mandated, not left as an option.
3. Test the account disable process
Ask how quickly a disabled account actually loses access, and confirm this during a trial rather than taking it on trust.
4. Review a sample session log
Ask for a sample export of a session log to check it captures the fields your own audit or compliance process will need.
5. Ask for the data residency answer in writing
Confirm where session data and metadata are processed and stored, and get this in writing if it affects your obligations.
6. Request a data processing agreement
Ask for a DPA naming the vendor's subprocessors, particularly hosting providers, before signing.
7. Clarify pricing and exit terms
Confirm whether pricing is fixed or variable, and what happens to your data and access if you cancel the contract.
8. Ask about the vendor's own security testing
Ask whether and how often the vendor's product undergoes penetration testing or vulnerability assessment.
Common pitfalls
- Accepting a general claim of encryption without confirming the specific standard used
- Not testing how quickly a disabled account actually loses access
- Assuming session logs capture enough detail without reviewing an actual sample export
- Signing a contract before confirming where data is processed and stored
- Overlooking what happens to your logs and recordings if you later cancel the service
What to measure
| Vendor questions answered in writing | Track before signing, not after |
|---|---|
| Time for account disable to take effect | Test during trial, target immediate |
| Sample log fields reviewed | Confirm before purchase, not after go-live |
| Data processing agreement obtained | Yes or no, before contract signature |
Select any column heading to sort.
Frequently asked questions
- What is the single most important question to ask a remote access vendor?
- There is no single most important question since the areas interact, but confirming the encryption standard, whether named accounts and enforceable MFA are supported, and where data is processed together cover the highest-impact risks most organisations need to understand before buying.
- Should we expect a vendor to share penetration testing results in full?
- Not necessarily in full technical detail, since vendors often treat specific findings as sensitive, but a mature vendor should be able to describe its testing cadence and general approach, and a vendor unwilling to discuss this at all is worth treating with more caution.
- Why does it matter whether pricing is fixed or variable?
- Variable, usage-based pricing can make budgeting difficult and may create an incentive to under-use a security-relevant tool to control cost, whereas fixed pricing removes that tension, though the right choice depends on how predictable your usage actually is.
- What should happen to our data if we cancel a remote access contract?
- You should get a clear answer before signing about whether logs, recordings and configuration data are deleted, retained for a defined period, or exportable, since assuming this without asking can leave data in an unclear state after the relationship ends.
- Is it reasonable to ask a vendor for a sample session log before buying?
- Yes, this is a reasonable and common request during a trial or proof of concept, and reviewing an actual export is a more reliable way to confirm logging capability than relying on a feature list alone.
Sources
Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.
- Guide to Enterprise Telework, Remote Access and BYOD Security (SP 800-46 Rev. 2)
NIST
Federal guidance on the security properties expected of remote access technology and vendors.
- Cyber Essentials
NCSC
Reference point for the baseline access control, patching and configuration questions worth asking a vendor.
- Guide to the UK General Data Protection Regulation (UK GDPR)
Information Commissioner's Office
Relevant to questions about data processing agreements, subprocessors and data residency.
Putting it into practice
This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.
More best-practice guides
Remote access audit evidence
How to build an audit evidence pack for remote access, covering logs, approvals, access reviews and retention records.
Data residency & remote support
What data residency and international transfer rules mean for remote support, and where session traffic and metadata actually go.
Benefits of remote desktop
A vendor-neutral guide to what remote desktop access is good for: faster troubleshooting, centralised patching, fewer site visits, business continuity and keeping sensitive data off local devices.