Security

How VendorMist Protects Vendor Records, Contracts, And Source Evidence

Encryption in transit and at rest, workspace isolation, retention controls, and audit logs for discovery, renewal decisions, and webhook delivery.

  • TLS 1.3 for all ingest · AES-256 at rest for contracts, invoices, and exports
  • Workspace-scoped storage — no cross-tenant vendor records or source files
  • Configurable retention aligned to portfolio estimator · automatic purge jobs
  • RBAC for discovery, dossier, review room, and portfolio surfaces
  • SSO / SCIM on Enterprise plans · named admin audit for brief exports
  • SOC 2 Type II in progress · DPA and SCCs available for enterprise

Data Processing Addendum · Contact security