Privacy Settings
Thinking

Answering Security and Pricing Questions on Sales Calls

6 min read

The questions that stall B2B deals rarely come from the demo. They are the technical questions on sales calls: where is our data stored, are you SOC 2 certified, what does this cost at 500 seats, does this work with our SSO.

When one of these lands, a rep has three options. Freeze, and the buyer wonders who actually knows the product. Guess, and risk a wrong compliance answer that kills trust or creates real liability. Defer, and watch a live buying conversation turn into an email thread that dies in procurement. None of these is good, and the fix is not to turn every rep into a security expert. It is to know, for each question type, what a rep can safely say live and where the real answer lives in the organisation.

Why do technical questions stall deals?

Because they come from a different buyer. The demo audience wants to see the product work. Security, legal, IT and finance want evidence they can file. Their questions have exact answers, and they will check those answers later against your documentation, your contract, and what other vendors told them. A wrong answer makes every other claim on the call suspect.

The pattern that works is the same for every category below: answer what is documented, name where the evidence lives, and offer the right specialist. Buyers do not penalise a rep for saying "I will confirm that today." They penalise a confident answer that turns out to be wrong.

Are you SOC 2 certified? Handling security posture questions

Why it gets asked: the buyer's security team uses certifications as an early filter. If the answer is unclear, some will disqualify the vendor before an evaluation starts.

What a good answer sounds like: "Our security documentation, including our current certifications and latest penetration test summary, lives in our trust centre. I can send you access today, and our security lead can join a call with your team this week."

Notice what that answer does not do. It does not name a certification the rep has not personally seen documented. If you are unsure whether the company holds SOC 2 Type I or Type II, do not pick one. Say you will confirm the exact scope. A rep who claims the wrong audit type creates a written record that legal has to walk back.

Where the truth lives: the security team, a trust centre page, and a maintained set of standard security questionnaire answers. If your organisation has none of these, that gap, not rep training, is the real problem.

Where is our data stored? Data residency and GDPR questions

Why it gets asked: legal and procurement need residency, data processing terms and sub-processor lists before they can sign. EU buyers in particular will ask about GDPR early, because a bad answer saves them weeks of wasted evaluation.

What a good answer sounds like: "Data is hosted in the regions listed in our documentation, our data processing agreement and sub-processor list are public, and I will send both after this call."

What a rep must never improvise: retention periods, deletion guarantees, whether customer data trains models, and anything about how a specific clause would be amended. These answers surface again in legal review, and a mismatch between what the rep said and what the DPA says reads as bad faith even when it was an honest mistake.

Where the truth lives: legal, plus the published DPA, privacy policy and sub-processor page. The rep's job is to route to those documents fast, and this is where teams increasingly want SE help on every call rather than a promise to follow up.

What does this cost at 500 seats? Pricing structure questions

Why it gets asked: a budget owner is testing whether the deal is plausible before investing more time. It is a fair question, and "I can't discuss pricing" sounds evasive.

What a good answer sounds like: "Pricing is per seat with volume tiers. At that size you would be in our enterprise band, and I can get you a proper quote within a day. What I can tell you now is how the tiers are structured."

Give structure live and numbers in writing. An improvised figure becomes the anchor for the whole negotiation, and a discount mentioned casually on a call gets repeated back as a promise three months later. Only quote list prices that are published.

Where the truth lives: the public pricing page for list terms, and RevOps or the deal desk for volume and discount rules.

Does this work with our SSO? Integration questions

Why it gets asked: IT is estimating rollout cost. SSO, provisioning and CRM connections decide whether adoption takes a week or a quarter.

These are the most answerable questions on this list, because they are binary and documented. A good answer names exactly what the integrations page lists and gives a plain "not today" for anything else. A false yes on SAML support dies one call later, in the technical evaluation, in front of the same people. The organisational fix is a public, current integrations page (ours is here) that reps trust enough to read from.

Where the truth lives: product documentation and the sales engineer.

The escalation rule: what never gets improvised

One rule covers every category. Answer what is documented. Never improvise legal or contractual commitments. And know the short list of questions that always go to a specialist, no matter how confident you feel:

  1. Custom DPA or data residency terms: legal.
  2. Liability, indemnity and security exceptions: legal.
  3. Certification scope and audit evidence: the security team.
  4. Non-standard discounts and payment terms: the deal desk.
  5. Roadmap dates presented as commitments: product, in writing.

The escalation itself can keep momentum if it comes with a name and a deadline: "That one goes to our security lead; you will have it in writing tomorrow" beats a vague follow-up.

Who owns the truth for each question type

Question typeWho owns the truthSafe live answer pattern
Security posture (SOC 2, pen tests)Security team, trust centreState only documented certifications; offer the report and the security lead; confirm scope rather than guess it
Data residency and GDPRLegal; the DPA and sub-processor listName documented regions and the DPA; escalate retention, deletion and model-training specifics
Pricing at volumeRevOps or deal deskExplain the model and tiers live; commit to a quote deadline, never an improvised number
SSO and integrationsProduct docs, sales engineeringConfirm only what the integrations page lists; a plain no for the rest

The table is the training artefact. A rep who knows the right column for each row never has to freeze or guess.

The last gap is recall under pressure, because knowing where the answer lives does not help mid-sentence on a live call. This is where a realtime assistant earns its place: Caretta listens to the conversation and surfaces the documented answer, pulled from your security docs, pricing rules and past calls, at the moment the question lands, the way real-time AI finds answers on live sales calls. The rep reads from the source instead of remembering it.

Want the documented answer on screen the next time a buyer asks about SOC 2? See it live: book a demo.

Frequently asked questions

Should sales reps answer security questions on sales calls?
Yes, but only from documented sources. A rep can safely state anything that appears in the company's trust centre, security questionnaire answers, or public documentation. Anything beyond that, including certification scope and audit details, should go to the security team rather than be guessed live.
What should a rep say when asked about SOC 2 certification?
State only what the company has documented and offer the evidence: the trust centre, the audit report under NDA, or a call with the security lead. If the rep is not certain of the exact certification or its scope, the safe answer is to confirm and follow up the same day, never to pick an answer that sounds right.
How do I answer pricing questions without giving a quote?
Explain the pricing model rather than a number: what the unit is, whether volume tiers exist, and which band the buyer's size falls into. Then commit to a deadline for a real quote. Improvised numbers become anchors, and casually mentioned discounts get treated as promises.
Which technical questions should always go to legal or a sales engineer?
Anything that creates a commitment: custom data processing terms, liability and indemnity, security exceptions, data retention or deletion guarantees, non-standard discounts, and roadmap dates. Reps can describe what is documented today; they should never improvise contractual or legal positions.
Back to the blogMore notes from Caretta.

The answer, right when your rep needs it.