Security
How VendorMist Protects Vendor Records, Contracts, And Source Evidence
Encryption in transit and at rest, workspace isolation, retention controls, and audit logs for discovery, renewal decisions, and webhook delivery.
- TLS 1.3 for all ingest · AES-256 at rest for contracts, invoices, and exports
- Workspace-scoped storage — no cross-tenant vendor records or source files
- Configurable retention aligned to portfolio estimator · automatic purge jobs
- RBAC for discovery, dossier, review room, and portfolio surfaces
- SSO / SCIM on Enterprise plans · named admin audit for brief exports
- SOC 2 Type II in progress · DPA and SCCs available for enterprise