Compliance
What to ask a security vendor: DPA, EULA, exit
Twelve questions for a malware-scanner purchase, mapped to the EU supplier clauses and Art. 28 GDPR, plus the exit questions the cxs wind-down taught us.
Buying a malware scanner used to be a technical decision with a purchase order attached. For a European hosting provider it is now a supply-chain decision with a documentation requirement attached, and the questions below are the ones we would want answered before signing — including about ourselves.
Why the list exists now
Two things changed.
First, the category lost its incumbent. Way to the Web announced on 30 July 2025 that it would close permanently on 31 August 2025. That was a planned, well-handled wind-down — but for customers it meant a frozen signature database, a switched-off reputation backend, and licences that could no longer be reactivated or moved to a new server IP. “What happens to my installation if you stop trading” stopped being a philosophical question.
Second, asking became mandatory for many buyers. Commission Implementing Regulation (EU) 2024/2690 , in force since 7 November 2024, is directly applicable — no national transposition needed — and binds cloud providers, data-centre providers, managed service providers, managed security service providers and DNS providers. Its Annex sets out a mandatory list of supplier-contract clauses, requires a registry of direct suppliers, and requires that suppliers be re-evaluated over time. In Germany, § 30 BSIG additionally requires supply-chain measures and requires that compliance be documented (BSIG 2025 ); whether you are in scope is a question of category and size, and the BSI publishes its own scoping information .
The clauses the regulation names for supplier relationships are, in substance:
- secure development procedures;
- staff training, certification and background checks;
- incident notification without undue delay;
- audit rights or audit reports;
- vulnerability handling;
- subcontracting terms;
- data retrieval and disposal at the end of the contract.
It also names the ability to diversify sources of supply and limit vendor lock-in as a supply-chain criterion. Those points track Art. 28(3) GDPR closely enough that one vendor questionnaire can serve both frameworks.
The twelve questions
What the software does with data
1. Does a default installation send file contents anywhere? Not “can it be turned off” — what does the default do? Ask for the configuration key and its default value.
2. What else leaves the machine? File names, full paths, hashes, domain names, IP addresses, verdicts, usage telemetry. Each is a separate answer.
3. Can the outbound behaviour be disabled, and does the product still work if it is? A feature that degrades to nothing without a cloud call is a cloud product with a local installer.
4. Which document governs when they disagree? Ask for the technical documentation, the DPA and the licence terms, and compare what each says about data flows. This is not a hypothetical in this market: vendor documents in this category do sometimes describe different data flows, and a buyer is entitled to ask which one is binding. A worked example is in Imunify360 versus Shelltrap for CyberPanel .
5. Where does processing happen, and who are the sub-processors? An EU-registered company is not the same as EU-only processing. Ask for the sub-processor list with countries, and whether a region can be selected. The data-protection background is in GDPR and data residency in malware scanning .
Assurance
6. How are releases built and signed, and how do I verify them? You want an artefact-level answer: checksums, detached signatures, a published key fingerprint, and the exact verification command.
7. How are vulnerabilities in the product handled? A security contact, a disclosure policy, an advisory channel, and a stated response expectation.
8. Do you have an audit report, or a contractual audit right? Either is acceptable; neither is a marketing page.
9. What are your personnel controls? Training, certification and background checks are named clauses, not nice-to-haves, for in-scope buyers.
Continuity — the questions the last twelve months made unavoidable
10. If the company stops trading, what keeps working? Does the scanner keep running unlicensed, does it fail closed, does it stop scanning? Get the behaviour in writing.
11. Can a licence follow a server rebuild or a migration? This is exactly what bit cxs customers. Ask whether deactivation and reactivation are self-service.
12. Can I export my data in an open format? Findings, quarantine metadata, audit records, policies. If the only interface is the vendor’s UI, you have a lock-in problem the regulation asks you to consider.
How to score the answers
- Anything that only exists in a sales email is not an answer; it needs to be in documentation or the contract.
- “We don’t send files” should come with a pointer to the line in the technical documentation that says so.
- Record the answers in your supplier registry with the date and a re-review interval. Vendors change defaults, and the regulation expects re-evaluation rather than a one-off form.
- Re-check anything time-sensitive — prices, sub-processor lists, legal status of transfer mechanisms — at renewal.
Our own answers, for the record
Because a vendor publishing a questionnaire and then dodging it would be absurd, here is where Shelltrap stands, from its own documentation:
- File contents: by default no file, no sample and no telemetry leaves the host. Logs contain no secrets and no file contents.
- Outbound connections: two, both to Panomity in Germany — licence activation/renewal (licence key, server fingerprint, hostname, version, OS) and signature feed downloads authenticated with the licence token. The daemon’s own unit restricts address families to
AF_UNIX; network access for notifications exists only if you install the drop-in and configure SMTP or webhook targets. - Release integrity: each release consists of four package artefacts, each with a
.sha256and a detached.ascsignature, verifiable withgpgvagainst the published key; package bytes are reproducible given identical pinned build inputs. - Continuity: without a valid licence the daemon does not crash — it reports
unlicensed, stops scanning, and the upload gate answersallowwith that reason. Licences are per server and bound to a fingerprint;shelltrap license deactivatefrees the slot so a rebuilt server can be activated again. - Export: findings, quarantine entries, policies, feed generations and the audit chain are all readable as JSON over the local API and CLI.
- Source: Shelltrap is proprietary and ships as compiled binaries with the PHP adapter and the CyberPanel plugin; there is no source in the package. If source escrow matters to your procurement, ask for it explicitly rather than assuming.
- Security contact:
security@shelltrap.com. Vendor: Panomity GmbH, Bavaria, Germany.
What this means for CyberPanel operators
- Turn this list into your standard vendor pack and send it to every candidate, including incumbents at renewal.
- Put the answers in a supplier registry with a review date; § 30 BSIG expects documented compliance, and the registry is the cheapest part of it.
- Weight the continuity questions properly. The last year proved that a well-run vendor can still close, and licence portability after a rebuild is a five-minute question with a long tail.
- Compare the answers against the field before you commit — the current options and prices are in CXS alternatives in 2026 , and installation specifics are in the installation docs .
Shelltrap is a German per-server product that scans locally, ships signed packages, and lets you take your data with you. See pricing .
Frequently asked
Is this list only relevant to regulated companies?
The legal obligation applies to in-scope entities, but the questions are useful to anyone. They are the questions whose answers you wish you had after a vendor stops trading or after an incident, and the paperwork burden of asking them upfront is one email.
Why does 'what happens if you disappear' belong in a security questionnaire?
Because the EU implementing regulation names the ability to diversify supply and limit vendor lock-in as a supply-chain criterion, and because the category has just watched a 25-year-old vendor close. Asking is doing what the rules expect.
Can one questionnaire cover GDPR and NIS2?
Largely, yes. The supplier-contract points on incident notification, audit, vulnerability handling, subcontracting and data disposal track Art. 28(3) GDPR closely enough that a single vendor pack can answer both, with the data-protection specifics added.
Sources
Every number, date and vendor claim in this article links to one of these.
- Commission Implementing Regulation (EU) 2024/2690 — accessed 2026-09-04
- Regulation (EU) 2016/679 (GDPR), consolidated text — Art. 28 — accessed 2026-09-04
- BSI-Gesetz 2025 (consolidated text, § 30 risk-management measures) — accessed 2026-09-04
- configserver.com closure announcement, archived 30 July 2025 — accessed 2026-09-04
- BSI — NIS-2 regulated entities (registration information) — accessed 2026-09-04
More from the research desk
NIS2, GDPR and malware scanning for hosting providers
Germany's NIS2 law is in force since 6 December 2025. What it obliges hosters to do, what the BSI requires, and how a …
ComparisonsClamAV alone is not enough for webshells
ClamAV says so itself. What the engine covers, where PHP webshell detection actually comes from, and what a layered …
ComparisonsCXS alternatives in 2026: the honest field guide
ConfigServer closed on 31 August 2025. What replaced cxs, what the options cost as at 4 September 2026, and what runs on …
Shelltrap watches the files this article is about
Real-time detection, an upload gate in front of your PHP, explainable verdicts, and nothing leaving your server.