Everything a vendor review asks for, before it asks.
Certification scope and audit dates, the complete subprocessor list with data classification per party, the disclosure timetable we hold vendors to, and the channel for reporting weaknesses in our own estate. Dated, scoped, and specific enough to check.
Certifications and audit reports
Reports are available under NDA through your engagement lead. We do not publish audit reports to the open web.
Who else can touch your data
This list is complete. Clients under contract are notified 30 days before any addition, and may object.
We do not use analytics, advertising, session-replay or AI subprocessors. Evidence never leaves the estate listed above, and is never used to train a model.
Found something in our systems?
Monitored continuously. We acknowledge within one business day and will not pursue anyone acting in good faith under this policy.
Tell us and we will treat it exactly as we ask vendors to treat ours: acknowledged, scoped, fixed, and credited.
We do not run a paid bounty. We do publish the fix, name the reporter if they want it, and say what we changed.
