Reliability belongs in vendor evaluation alongside product fit, price, and support. These questions are intended to produce documents and named owners, not a generic score.

1. What status information is public?

Ask for the public status page, component list, incident history, and subscription options. A status page is useful evidence, but its absence or presence should not be treated as a complete measure of operational maturity.

2. Which availability target applies to our plan?

Request the exact service, region, measurement window, exclusions, credit schedule, and claim process. A provider-wide marketing percentage may not apply to the product you are buying.

3. How are incidents communicated?

Identify where initial notices, progress updates, resolution notices, and post-incident reports appear. Confirm whether customer-only notices require access that could be unavailable during an identity incident.

4. What is the recovery design?

Ask about the relevant failure domains, recovery-time objective, recovery-point objective, and the last exercise of the recovery plan. Focus on the service you will use rather than a broad company architecture statement.

5. What happens to work in progress?

Determine whether writes, messages, jobs, and transactions are rejected, queued, retried, duplicated, or lost during an outage. Ask how customers reconcile work after recovery.

6. How will we retrieve our data?

Verify export formats, frequency, API limits, retention, and the process for retrieving data during a prolonged outage or contract termination. Test the export before it is needed.

7. When is maintenance performed?

Record normal maintenance windows, notice periods, expected customer effect, and any options for customers in different time zones.

8. Which dependencies affect the service?

Ask which cloud, identity, communications, and other material providers are in the service path. The vendor may not disclose every detail; record what is confirmed and avoid assuming unconfirmed architecture.

9. Who owns escalation on both sides?

Document support channels, severity definitions, response targets, named customer contacts, and the internal owner responsible for escalation. Test the route before a critical incident.

10. What is the exit plan?

Record termination notice, data export, deletion timing, migration assistance, and the operational plan if the vendor discontinues the product.

Keep the result usable

Attach the answers and source documents to the vendor record. Mark unanswered questions, assign an owner to accepted risks, and review the record when the plan or architecture changes.

ServiceAlert can help track public operational notices for vendors in your service path. Security investigations and security posture work remain separate from this reliability workflow.

Browse monitored services or review dependency monitoring.