Hermes Wiki

VendorRisk

Vetting SaaS/vendor dependencies for security, financial stability, and lock-in risk before adoption.

Why we need this / what value this brings

An unvetted vendor dependency can become a lock-in trap or a security liability discovered too late.

When to use this

Before adopting any new significant vendor/SaaS dependency (auth provider, payment processor, hosting).

How to use or implement this

Write a brief assessment (cost at scale, lock-in risk, security posture) before committing — see the existing Anti-Lockin-Pattern-for-Startup-Stack.md as a starting reference.

Research questions

  • Clerk, whatever payment provider, hosting — has a lock-in risk assessment ever been written down? See Anti-Lockin-Pattern-for-Startup-Stack.md.

Empty folder — drop notes, links, and findings here as you research.

Hermes Wiki