Security and compliance evidence
Start with independent audits rather than marketing claims. A mature mail vendor can share audit evidence under NDA during vendor review instead of asking you to take controls on faith. DIS Direct's SOC 2 Type II environment and HIPAA controls were audited by Thoropass, and detailed reports are shared directly with qualified customers.
- SOC 2 Type II report, current period, from a named auditor
- HIPAA controls evidence if PHI ever touches the program
- Access controls for data files and proofs
- Sustainability scoring if your company requires it (EcoVadis)
Capacity and continuity
A vendor that fits your program at peak matters more than one that fits it in January. Ask for daily throughput by operation, not just annual volume, and confirm the work happens in the vendor's own plant on one schedule rather than through undisclosed subcontracting.
- Daily capacity by operation: printing, addressing, inserting, finishing
- Single-plant accountability or a disclosed partner network
- Seasonal surge history in your industry's peak window
- Equipment list that matches the promised throughput
Data handling and file transfer
Mailing lists are customer data. Verify how files move, who can touch them, and how long they are retained. Secure transfer should be the default path, not an email attachment.
- Encrypted, access-controlled file transfer
- Documented data retention and destruction practice
- CASS, NCOA, and suppression processing in-house
Postal performance and documentation
Postage is usually the largest line on the invoice, so the vendor's postal paperwork is where quoted savings become real or evaporate. Ask how presort levels are achieved and documented, and how induction is planned.
- Presort documentation and postage statements for each drop
- Entry planning: SCF, destination entry, drop shipping
- Intelligent Mail barcode usage and tracking visibility
Commercial and white-label terms
For printers and agencies, confidentiality is a commercial term, not a courtesy. Confirm blind shipping, unbranded packing, and client-protection terms in writing, along with the ordinary vendor file: insurance certificates, W-9, and references from programs at your volume.
- Blind shipping and white-label protections in writing
- Certificate of insurance and W-9 on request
- References from programs of comparable volume and complexity
Sources
Primary references. Postage and product rules change, so confirm current USPS rates and standards before you mail.
- HHS: HIPAA for Business AssociatesWho counts as a business associate and what the rules require.
- AICPA & CIMA: SOC 2 reportsWhat a SOC 2 examination covers.
- USPS Postal Explorer: mailing standardsDMM references for preparation and documentation.
Frequently asked
- What documents should a direct mail vendor provide during due diligence?
- Expect current security audit evidence such as a SOC 2 Type II report, HIPAA controls evidence where relevant, a certificate of insurance, a W-9, equipment and capacity detail, and sample postal documentation. Mature vendors share audit reports under NDA during vendor review.
- How does DIS Direct handle vendor review requests?
- Public pages summarize the production path, and detailed reports, assessments, and contractual evidence are shared directly with qualified customers during vendor review. Thoropass audited DIS Direct's SOC 2 Type II environment and HIPAA controls.
- How should procurement evaluate capacity claims?
- Ask for daily throughput by operation rather than annual totals, confirm which operations run in the vendor's own plant, and check surge history in your peak season. DIS Direct reports addressing capacity above one million postcards per day and finishing capacity above five hundred thousand pieces per day.
- Why does white-label protection matter in vendor selection?
- When a printer or agency resells production, the plant partner's confidentiality terms protect the client relationship. Blind shipping and unbranded packaging should be standard written terms, not informal promises.
