Security & Trust

v3ndor.io is a vendor risk management platform. We hold customer data that is, by its nature, sensitive — vendor inventories, due diligence questionnaires, contracts, risk findings, and the people involved in remediating them. We treat that data accordingly.

This page is a public summary. Customers under NDA can request our full Trust Pack (penetration test letter, DPIA, network diagram) by emailing security@v3ndor.io. A SOC 2 report and a full BCP/DR plan are not yet available; ask and we will tell you where each stands.

1. Certifications & attestations

FrameworkStatusScope
NIST 800-53 (rev. 5)Aligned (Moderate baseline)Self-assessed control mapping; not a certification
GDPR / UK GDPRCompliantData Processor; DPA available on request
CCPA / CPRACompliantService Provider
HIPAANot in scopev3ndor.io is not currently a HIPAA Business Associate. Contact us if PHI is in your use case.

This table is the canonical statement of our compliance posture — where other v3ndor material describes a framework differently, this page governs. For our current attestation status against a specific framework, including SOC 2 and ISO/IEC 27001, or to request evidence under NDA, contact security@v3ndor.io.

2. Architecture & tenant isolation

3. Data protection

Encryption in transit

Encryption at rest

Backups

Data residency

Production data is hosted in a single United States region — Azure East US 2. We do not offer a per-customer choice of hosting region today, and EU-only or UK-only residency is not yet available. If you have a hard data-locality requirement, raise it with security@v3ndor.io before you sign.

4. Access control & authentication

Customer access

Internal access

5. Secure development lifecycle

6. Logging & monitoring

7. Vulnerability management

8. Incident response

9. Business continuity & disaster recovery

10. Vendor & sub-processor management

11. Privacy controls

12. Vulnerability disclosure

We welcome reports from security researchers. If you believe you have found a security vulnerability in v3ndor.io, please email security@v3ndor.io with:

Safe harbor

We will not pursue legal action against researchers who:

Out of scope

PGP

We do not publish a standing PGP key. For sensitive reports, request a per-incident key at security@v3ndor.io and we will supply it along with its fingerprint.

13. Contact

← Back to Legal hub