We are planning to buy a product that's developed on ASP.NET MVC, JQuery, SQL 2005. .basically latest MS stack. This product is going to store some of very highly sensitive data.
So, we need to evaluate that product in terms of security.
But I'm confused as in How can I certify that this product is secure and we can buy it.
I don't have the luxury to peep into source code unless I buy that product.
What are the options I have?