<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Third-Party-Risk on KilPen Technical Services - IT with Aloha</title><link>http://kilpen.com/tags/third-party-risk/</link><description>Recent content in Third-Party-Risk on KilPen Technical Services - IT with Aloha</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 18 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="http://kilpen.com/tags/third-party-risk/index.xml" rel="self" type="application/rss+xml"/><item><title>Third-Party &amp; Vendor Risk Management</title><link>http://kilpen.com/client-security-guides/third-party-risk-management/</link><pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><guid>http://kilpen.com/client-security-guides/third-party-risk-management/</guid><description>&lt;p&gt;&lt;strong&gt;Applies to:&lt;/strong&gt; Any small organization, nonprofit, or team that relies on outside vendors and SaaS tools — accounting software, a CRM or donor database, email and file storage, a payment processor, contractors, and the dozens of apps connected to them.&lt;br&gt;
&lt;strong&gt;Audience:&lt;/strong&gt; Organizations with little or no dedicated IT/security staff and a limited budget, who still need to take reasonable, defensible care of the data their vendors touch — including donor, client, member, and financial data.&lt;/p&gt;</description></item><item><title>Vendor Security Requirements (Send to Your Vendors)</title><link>http://kilpen.com/client-security-guides/vendor-security-requirements/</link><pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><guid>http://kilpen.com/client-security-guides/vendor-security-requirements/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;For our clients — how to use this page (do not send this box).&lt;/strong&gt; This is the &lt;strong&gt;vendor-facing companion&lt;/strong&gt; to our &lt;a href="../third-party-risk-management/"&gt;Third-Party &amp;amp; Vendor Risk Management guide&lt;/a&gt;. The section below the line is written to be &lt;strong&gt;sent directly to a vendor&lt;/strong&gt; that handles your data. Fill in the bracketed fields (&lt;code&gt;[…]&lt;/code&gt;), delete this instruction box, and send it as an email, a PDF, or an attachment to a contract or statement of work. Send it to the vendors in your &amp;ldquo;crown-jewel&amp;rdquo; bucket — the ones that touch personal data, money, or your accounts. For large providers (Google, Microsoft, Stripe, etc.), expect them to answer by pointing you to their security/trust page rather than replying point by point; that&amp;rsquo;s acceptable. KilPen can help you tailor or send this.&lt;/p&gt;</description></item></channel></rss>