Dev.to Security 🔐 Cybersecurity 👁 0 📖 6 min read

How to audit a Denver security vendor before you sign anything: a 6-question technical checklist

Three competing bids on a single LoDo deployment. Three completely different numbers. The lowest came from a single-page website with a phone number. The middle came from an operator who surfaced license number, insuranc

Three competing bids on a single LoDo deployment. Three completely different numbers. The lowest came from a single-page website with a phone number. The middle came from an operator who surfaced license number, insurance cert, and references inside one call. The highest came from a name the facilities lead already recognized from a competitor's property.

If you're building or running security operations — dispatching officers, managing vendor relationships, or plugging third-party providers into a broader physical security stack — you already know price signals almost nothing about compliance posture. What actually signals it is how fast a vendor produces documentation when you ask for it before you discuss anything else. Two of those three vendors treated that request as normal. One asked why it was needed "right away." That reaction is your entire pre-qualification process compressed into a single moment. Everything below is how to engineer that moment on purpose.

The regulatory floor in Denver

Denver's security market runs under Denver Municipal Code Ch. 32 (Dept. of Excise and Licenses). That's the actual enforceable floor — not a certification body, not a trade association, a municipal code with a licensing portal you can query yourself. The metro population is 2.9M, with documented risk concentration in four precincts: Downtown / LoDo, Cherry Creek, RiNo Art District, and Capitol Hill. Risk patterns split along two axes: nightlife incidents (Downtown / LoDo, Cherry Creek) and event-day crowd safety (Cherry Creek, RiNo, Capitol Hill). If you're managing deployments at stadiums, convention centers, or concert venues in any of those precincts, the operator you're contracting with needs to be compliant at both the company level and the individual officer level — and those are two separate license requirements.

Factor Denver detail
Metro population 2.9M
Key precincts Downtown / LoDo, Cherry Creek, RiNo Art District, Capitol Hill
Primary risk patterns Downtown nightlife incidents, event-day crowd safety
Major venue categories Stadiums, convention centers, concert venues
Governing law Denver Municipal Code Ch. 32 (Dept. of Excise and Licenses)

The 6-question pre-qualification audit

Run these in sequence, in a single call, before any pricing conversation. A compliant provider answers all six without needing to "check with the office" — the documentation already exists because they maintain it as a normal operating cost, not a special request.

1. Operator license number under Denver Municipal Code Ch. 32?
Get the number. Look it up yourself on the licensing portal. Do not accept "we're licensed" as a substitute for a number you can verify independently. This is the fastest single filter in the process — hesitation here has already answered the rest.

2. Are individual officers separately licensed under Ch. 32?
This is the most common compliance gap in Denver's vendor pool: valid company license, unlicensed deployable roster. Ask for individual officer license numbers for the specific people assigned to your deployment — not a company-wide assurance. If they can't produce per-officer numbers for named assignees, the roster isn't compliant regardless of what the company-level cert says.

3. Certificate of insurance — limits and additional insured status?
$1M per occurrence minimum. Your property or event named as additional insured. Request the cert before you confirm the engagement. A vendor who can't produce it within the same business day is not carrying the coverage they're implying. Read the cert yourself — entity name, expiration date, coverage scope. "We're covered" is not a data point.

4. Documented deployment history in your specific Denver precinct?
Downtown / LoDo and Cherry Creek carry different risk exposure than RiNo and Capitol Hill. A vendor with genuine local depth can describe the nightlife incident pattern at LoDo venues specifically — not recite a generic crowd-management philosophy. If they can't distinguish precinct dynamics without prompting, they're quoting from a template.

5. Background check specifics — what's verified, and how recently?
Criminal history, employment verification, license standing under Ch. 32 — for the specific officers assigned to you, not the general population. "We background check everyone" is not an answer. The specifics are.

6. Substitution protocol — how is a no-show handled, and is the replacement's Ch. 32 license verified before they arrive?
Not after. Before. This is where compliance gaps surface operationally: a vendor manages a licensing hole on their roster by filling shifts with whoever's available, and your deployment ends up with an officer whose individual license status was never confirmed for that date. Get the substitution protocol in writing.

Pro tip: Ask all 6 questions in the same phone call, before discussing price. A provider's speed and specificity in answering — not their sales pitch — is the actual signal. Providers who are fully compliant in Denver answer within minutes because the documentation already exists. Providers who are not compliant need time, because the documents do not yet exist to produce.

Red flags specific to Denver's vendor pool

Vague precinct history. A provider who can't describe the nightlife incident dynamic at a LoDo stadium event without being prompted is quoting from a generic script. That's not local depth.

Named officers TBD until 24 hours out. This is almost always a Ch. 32 licensing gap — the vendor is managing an unlicensed roster by delaying officer confirmation until they can find whoever's available.

Insurance cert naming the wrong entity or showing a lapsed date. Common pattern: a cert that technically exists but was issued for a different engagement or expired weeks ago. Read it yourself.

Quote significantly below Denver market rate with no structural explanation. Licensed, individually verified officers cost what they cost. A quote meaningfully under comparable coverage for LoDo or Cherry Creek venues usually means one of the 6 questions above has an answer the vendor would rather not give.

What goes in the contract after the audit passes

Vetting is not the contract stage. Once a vendor clears all 6:

  • Named officers with Ch. 32 license numbers attached as an appendix — updated on every substitution, not handled informally.
  • Insurance covering the full contract term — renewal is the vendor's responsibility to track and produce, not yours to chase.
  • Defined incident-reporting timeline — under Ch. 32, officers have a specific scope of authority; the contract should specify how incidents are documented and when you receive the report.
  • Termination tied to compliance failure, not just performance — if the vendor's Ch. 32 license lapses, or any assigned officer's individual license isn't current, you need clean exit rights without penalty. Compliance failure is a different category from a missed shift.

A fully compliant vendor won't push back on any of these. Resistance at the contract stage, after a clean audit conversation, is new signal.

One-time event vs. ongoing contract: where the emphasis shifts

The 6 questions apply in both cases, but the risk weighting changes.

Single event at a LoDo stadium or Cherry Creek convention center: prioritize crowd-management certification and confirmed named officers for that specific date. A vendor who's vague about exactly who is on-site for a one-off booking is the highest-risk pattern for events specifically — there's no ongoing relationship to correct the failure if something goes wrong.

Ongoing contract at a RiNo or Capitol Hill property: prioritize the substitution protocol and insurance renewal process. Month one performance tells you almost nothing about month twelve. The contract terms above are what protect the full engagement, not the initial vetting conversation.

The underlying Ch. 32 licensing requirement doesn't flex based on contract length. A one-night concert venue deployment in Capitol Hill requires the same individually licensed officers as a year-long commercial contract in Downtown / LoDo.

Where XGuard fits for operators building in this space

If you're on the operator side — running dispatch, managing vendor relationships, or building the infrastructure that connects clients to deployable officers — XGuard operates as a real-time marketplace and dispatch system where officer identity and Ch. 32 license status are verified before a guard appears in the pool. That pre-verification compresses the audit burden: instead of running the 6-question framework cold against every new vendor, you're confirming deployment fit for a specific LoDo or Cherry Creek engagement rather than starting compliance verification from scratch. XGuard is worth a look for operators who want to stop doing manual license lookups on every new hire or subcontractor before a shift goes live.

If you're building or managing security operations in Denver and want to see how the dispatch and verification layer works, check out XGuard — the operator onboarding flow is where to start.

Originally published at xguard.app. This version was adapted for this platform's audience; the canonical original lives at the link above.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.