Your huge customers should have a security standard for vendors. It is difficult to even start integrating with them if you don't pass some kind of assessment from them. If those were waived then you must have a hot product. You can also look at the standards for your customers and use those as a basis.
How do you deliver your product? If it is web based you have technical attack vectors. Do you have a safe and sanitized software delivery pipeline? A lot of web based SaaS pull from NPM, pip, etc... all of this software should be reviewed technically.
Where and how is customer data stored and transmitted. Is it encrypted at rest and in transit? Who controls passwords, are they hashed or is the it an Oauth integration?
Do you have internal controls (firewall, audit capability, permissions, separation of concerns, employee trainings, antivirus, backup procedures, ransomware procedures, disaster recovery policy) etc...
Good Luck!