Your Next Vendor Shortlist May Be Built from Stale Web Pages

By Neycho Tepavicharov, Co-founder, Flashcloud

Vendor evaluation has quietly changed shape, and most procurement processes have not caught up.

The early stages of a technology purchase used to involve reading. Someone visited a handful of supplier websites, skimmed the documentation, formed an impression, and built a shortlist from it. That reading was slow, but it had a useful property: the person doing it could see the context. A page that had obviously not been touched in years read differently from a page maintained weekly, and that judgment fed into the assessment without anyone thinking about it.

Increasingly, that first pass is delegated. An analyst asks an AI assistant which vendors serve a particular need, or what a specific supplier offers, and receives a summary. The summary is assembled largely from those same supplier websites, but stripped of every signal that would have told a human reader how much to trust it.

The result is a shortlist shaped by pages nobody at the vendor has looked at in some time.

Why this matters more than it sounds

The instinct is to treat this as a minor efficiency question. It is closer to a data quality problem, and it runs in two directions.

A capable supplier can be filtered out because its website understates what it does. Enterprise vendors are often worse at describing themselves than smaller ones, particularly where capability has grown through acquisition and the public site still reflects an older product boundary. If a summary is built from that page, the vendor appears not to do something it does.

The reverse is equally possible. A supplier whose site describes an ambitious roadmap, a since-deprecated integration, or a certification that has lapsed can appear stronger than it is. Nobody wrote those pages to deceive. They were accurate once and nobody owned them afterwards.

In both cases the failure is invisible to the buyer. There is no indication in a generated summary that the underlying source was three years old, or that a claim was aspirational when written. The output reads with uniform confidence regardless of the quality of what went into it.

The information that matters is the information least maintained

There is an unhelpful overlap between what these systems weigh and what organizations neglect.

Compliance certifications, supported integrations, regional availability, service boundaries, support commitments, pricing structures. These are the specifics a technical evaluator wants and a summary will surface. They are also, in most organizations, written once during a launch and revisited only when someone has a specific reason to.

Product documentation tends to be current, because engineering depends on it. Marketing pages describing what the company does are frequently not, because nothing internal breaks when they go stale. The public-facing description of a business is often the least governed material it produces, and it is now doing more work than it ever has.

Availability is part of the picture

There is a technical dimension worth noting. Systems gathering information move quickly across many sources. A site that responds slowly, times out, or is briefly unreachable at the moment it is visited does not produce a visible error. It is skipped, and whatever alternative source responded is used instead.

For a buyer, this means a vendor’s own site may not be the source a summary was actually built from. A third-party listing, an outdated comparison page, or a competitor’s marketing material may have filled the gap. The evaluator has no way of knowing which.

What a reasonable process looks like

None of this argues against using these tools in evaluation. They are genuinely useful for reducing a wide field to a manageable one. It argues for treating the output as a starting point rather than as evidence.

Three adjustments cover most of the exposure.

First, verify capability claims directly with the vendor before they influence a decision, particularly anything that would disqualify a supplier. A shortlist that quietly excluded a capable vendor is the more expensive failure, because nobody ever finds out it happened.

Second, treat absence of information as unknown rather than as absence of capability. This is the single most common misreading. A summary that does not mention a particular certification is not evidence the vendor lacks it. It may only be evidence that a page was written before the certification existed.

Third, ask when the underlying information was published, and be sceptical when that cannot be established. Any evaluation input whose age is unknown deserves confirmation before it carries weight.

None of this is onerous. It is the same scepticism a careful evaluator would have applied to an obviously dated website, restored to a process that has lost the visual cues which used to trigger it automatically.

The other direction

There is a symmetry here that is easy to miss. Every organization evaluating suppliers this way is also being evaluated. The same systems are describing it to prospective customers, partners and candidates, built from its own public pages.

For technology organizations this is often uncomfortable on inspection. The engineering documentation is current. The corporate site describing what the company does, which markets it serves, what it is certified for and who runs it, frequently is not. It sits between marketing, communications and nobody, and it has quietly become one of the more consequential assets the organization maintains.

The practical response is unglamorous and organizational rather than technical. Someone should be accountable for whether the public-facing facts about the business are true. The specifics most likely to be repeated deserve disproportionate attention. And it is worth periodically asking the assistants what they say about the organization, which takes minutes and which very few companies have done.

A governance problem, not a marketing one

The framing matters here. This is easily dismissed as a website maintenance issue, which is why it tends to sit unowned.

But when supplier selection is partly shaped by summaries of unmaintained pages, and when an organization’s own description to the market is assembled from material nobody has reviewed, the exposure is not a marketing exposure. It is a decision-quality problem on the buying side and a representation problem on the selling side, and both belong to whoever is accountable for how the organization makes and is subject to technology decisions.

For most enterprises that is a short list of people who have not yet been asked to think about it.

About the Author

Neycho Tepavicharov is co-founder of Flashcloud, a web hosting company. He has spent nearly two decades in the hosting and infrastructure industry, including co-founding and selling a previous hosting company. He writes about infrastructure operations and the practical realities of running customer-facing systems.