Skip to content

Trust at VendorVett

Last updated 25 September 2026

We sell due diligence, so we expect our customers to run it on us. This page answers the questions a security review asks first; for anything else, email security@vendorvett.com.

  • Reproducible scoring

    Every risk score is computed by a deterministic engine and shown with its working: the same answers always give the same score, and a reader can recompute it by hand. AI drafts narratives for review; it never produces a score.

  • Tamper-evident audit trail

    Every change is appended to a per-organization, hash-chained log. Altering or removing any entry breaks every digest after it, and owners can verify the chain at any time.

  • Verifiable evidence receipts

    On the Business plan, an assessment and its evidence can be exported as an Ed25519-signed receipt that anyone can check at vendorvett.com/verify without an account.

  • Tenant isolation

    Every request is scoped to one organization on the server, and an automated suite tries to cross tenants on every change. Roles (owner, analyst, viewer) are enforced by the API, not just the interface.

  • Encryption and file safety

    TLS in transit; documents encrypted at rest in private storage and reachable only through short-lived signed links. Every upload is virus-scanned, and a file that could not be scanned cannot be downloaded.

  • Staff access

    Our admin console is on an unpublished address, requires a second factor, locks out repeated failures and logs every support action. Support can view a customer account only through a time-limited, read-only session that the customer's screen clearly labels.

  • Backups

    Nightly encrypted backups stored off-platform, restored and verified every week, including a full check of every audit chain.

  • Your data rights

    Owners can export everything as a ZIP with a SHA-256 manifest, and delete their organization with a 30-day grace window. Payment failures never delete data.

Documents

Reporting a vulnerability

Email security@vendorvett.com with the details and how to reproduce it. We acknowledge within two business days, keep you updated, and will not pursue good-faith research that avoids harm to our customers and their data.

What we do not claim

VendorVett does not yet hold a SOC 2 report or ISO 27001 certificate. We will publish them here when we do, rather than describe controls as certified before they are.