Usually four things: the hosting platform and its security attestations, the security headers, where form submissions go, and who owns the accounts. I send a written setup summary for their file and join the review call. An engineering client's IT and security lead approved the static setup on that call.
The written summary covers:
- Platform. Netlify’s network, its compliance reports, TLS and DDoS mitigation.
- Headers. The exact security headers the site sends, which your team can check with any header scanner.
- Forms and data. Where submissions are stored and emailed, and whether sensitive ones should route into your own systems.
- Accounts and ownership. Who holds the domain, the repository and the hosting account. If IT wants them in the company’s name from day one, they can be set up that way.
- Optional layers. If your team wants a firewall and request logs in front of the site, Cloudflare can sit in front of it.
Go deeper: