Security and privacy
built from the ground up

VendoSec was engineered with security at its foundation — not as an afterthought. Every architectural decision, from infrastructure to data handling, is made to protect your vendor data and your customers' trust.

Compliance & Standards

Built for regulated industries

VendoSec aligns with major privacy regulations and security standards so your security team can deploy with confidence.

GDPR
EU Data Regulation
CCPA / CPRA
California Privacy Law
SOC 2 Type II
In preparation
HIPAA BAA
Available on Enterprise+

Privacy Practices

Your data belongs
to you

VendoSec acts as a data processor on your behalf. We do not sell, rent, or share your data with third parties for advertising or any commercial purpose outside of delivering the platform.

We collect only what is necessary to operate the service — organization and user information, vendor assessments, uploaded documents, and platform usage data for product improvement.

Personal data is retained only as long as needed to deliver the service or as required by law. Upon contract termination, customer data is deleted within 30 days upon request.

Your rights
  • Access or export your organization's data at any time
  • Request correction of inaccurate personal data
  • Request deletion of your data upon contract end
  • Opt out of non-essential communications
  • GDPR data subject requests honored within 30 days
  • CCPA opt-out of sale (we do not sell personal data)
  • Receive a copy of our Data Processing Agreement (DPA)

AI & Data Handling
  • SOC 2 analysis documents are not used to train AI models
  • Documents are handled ephemerally and not stored by AI Models
  • AI-generated analysis results are stored only by VendoSec
  • No vendor data is shared across organizations or used for product improvement without consent
  • AI outputs are advisory — human review is always required

Vendor & Assessment Data

Your vendor data
stays yours

All vendor profiles, assessments, and evidence are scoped to your organization only. Remediation tracking and notes never leave your tenant boundary.

Subservice organization and fourth-party data is stored under your organization partition. No vendor data is visible to VendoSec staff without explicit authorization from the customer.

Data export and deletion are available upon request per our Data Processing Agreement (DPA).