VendorRisk
Vetting SaaS/vendor dependencies for security, financial stability, and lock-in risk before adoption.
Why we need this / what value this brings
An unvetted vendor dependency can become a lock-in trap or a security liability discovered too late.
When to use this
Before adopting any new significant vendor/SaaS dependency (auth provider, payment processor, hosting).
How to use or implement this
Write a brief assessment (cost at scale, lock-in risk, security posture) before committing — see the existing Anti-Lockin-Pattern-for-Startup-Stack.md as a starting reference.
Research questions
- Clerk, whatever payment provider, hosting — has a lock-in risk assessment ever been written down? See Anti-Lockin-Pattern-for-Startup-Stack.md.
Empty folder — drop notes, links, and findings here as you research.