Skip to content
Resources / Security and trust

Built like the security products it assesses

Your vendor risk platform holds your vendors’ security evidence and your own control gaps. We protect it the way your CISO would expect: strong identity, isolated tenants, encryption, a complete audit trail and optional AI that is always accountable to a named reviewer.

Security architecture

Defense in depth, from sign-in to storage

The controls below are built into the platform for every customer. They are not add-ons.

Single sign-on

SAML and OIDC single sign-on with your identity provider, so joiners, movers and leavers are managed where you already manage them.

Mandatory MFA

A second factor is required on every password login. It is not an optional setting.

Tenant isolation

Each customer is a separate tenant, isolated in the database through row-level security as well as in the application.

Encryption

TLS in transit and encryption at rest for vendor records and uploaded evidence.

Full audit trail

Every sign-in, change, decision, sign-off and export is logged and can be exported for your auditors and examiners.

Least-privilege roles

Custom roles limit each user to the vendors, records and actions their job requires.

Segregation of duties

Multi-stage sign-off keeps the analyst, reviewer and approver of a decision separate.

Enterprise cloud hosting

The platform runs on a leading enterprise cloud provider with independently audited data centers.

Accountability

Every action has a name and a timestamp

Third-party risk decisions end up in front of auditors and examiners. The audit trail shows who did what, when and on which record, from evidence uploads to risk acceptances.

  • Sign-ins, role changes and configuration changes logged
  • Assessments, findings, remediation and risk acceptances recorded with the approver
  • Where AI is enabled, its outputs are logged alongside the reviewer’s edits and approval
  • Exports of the audit trail for internal audit and examiners
AI governance

AI with accountability

AI in VendRisk360 is optional: customers choose whether to opt in, and the platform workflow does not depend on it. Where it is enabled, it assists in two places only: completeness checks and key-date extraction on vendor evidence, and an AI-assisted first pass within SOC Report Review that the expert assessor verifies. The design follows the principles of the NIST AI RMF and ISO/IEC 42001: transparency, human oversight and traceability.

  • Every review, rating and sign-off is made by an expert assessor or the customer’s own reviewers
  • AI never rates risk, raises findings or signs off, and customers can choose expert-only reviews
  • Reviewers can edit or reject any suggestion, and the audit trail records the decision
  • Customer data is used to serve the customer’s own workspace
Your vendors’ data

A safe way for vendors to share evidence

Vendors send you SOC reports, penetration tests and policies they consider confidential. The vendor portal gives them a controlled way to do it.

One-time-code access

Vendors sign in with a one-time code sent to their email. No shared passwords, no new accounts.

Scoped requests

A vendor sees only the requests addressed to it, never your other vendors or your internal notes.

Encrypted uploads

Evidence is encrypted in transit and at rest and stored within your tenant.

Traceable handling

Uploads, reviews and decisions on each document are recorded in the audit trail.

Your security review

We expect to be assessed. Here is how we help.

You are evaluating a vendor risk platform, so you will run your own third-party process on us. We make that straightforward.

  1. 1

    Your questionnaire

    Send your standard security questionnaire. We complete it, rather than asking you to accept ours instead.

  2. 2

    Architecture overview

    On request, our team walks your security architects through identity, tenancy, encryption, logging and AI processing.

  3. 3

    Assurance documentation

    Ask about our current assurance status and the documentation we can share under NDA.

  4. 4

    Ongoing contact

    A named contact for security questions during and after your evaluation.

Vulnerability disclosure

Found a security issue? Tell us.

We welcome reports from security researchers and customers. Email security@vendrisk360.com with the details.

Please include

  • A description of the issue and where you found it
  • Steps to reproduce, and a proof of concept if you have one
  • Your contact details, so we can follow up

Please do not

  • Access, modify or delete data that does not belong to you
  • Run denial-of-service, spam or social-engineering tests
  • Disclose the issue publicly before we have had reasonable time to fix it

We will acknowledge your report, keep you informed while we investigate and let you know when the issue is resolved.

FAQ

Frequently asked questions

Which single sign-on protocols do you support?

VendRisk360 supports SAML and OIDC single sign-on with your identity provider. Where password login is used, a second factor is mandatory; it cannot be switched off.

How is our data separated from other customers’ data?

Every customer is a separate tenant. Isolation is enforced in the database itself through row-level security, so queries only return rows that belong to the requesting tenant, in addition to the checks in the application.

Is our data used to train AI models?

Customer data is used to serve your own workspace. AI is optional and only runs where you opt in: for completeness checks and key-date extraction on your vendors’ evidence, and for an AI-assisted first pass within SOC Report Review that the expert assessor verifies. Ask us during your security review for the detail of how AI processing is configured for your deployment.

Do you hold security certifications?

We do not list certifications on this page. Ask our team during your evaluation about our current assurance status and what documentation we can share under NDA.

Will you complete our security questionnaire?

Yes. Send us your standard questionnaire and we will complete it, and we can walk your security team through an architecture overview on request.

How do vendors access the platform?

Vendors use the vendor portal with one-time-code access. They see only the requests addressed to them and can upload evidence without creating an account or a password.

How do I report a vulnerability?

Email security@vendrisk360.com with a description, the steps to reproduce and any proof of concept. Please give us reasonable time to investigate and fix before any disclosure, and do not access or modify data that is not yours.

Get started

Put VendRisk360 through your security review

Send us your questionnaire, meet our team and see the controls described here in the product.