Tenant separation
Customer records are scoped to the owning organisation with server-side authorisation and cross-tenant access testing.
Security
VendorGuard is designed around strict tenant separation, controlled evidence access, clear accountability and secure product delivery.
Security controls are implemented and verified as the product moves through pilot readiness. Current assurance material is available during customer evaluation.
Customer records are scoped to the owning organisation with server-side authorisation and cross-tenant access testing.
Vendor documents are intended for private storage, short-lived access links, file validation, malware scanning and access logging.
Role-based access, MFA, secure sessions and separation between reviewer and approver responsibilities.
Security- and governance-relevant actions are recorded so customers can trace who performed each important action.
Automated testing, dependency and secret scanning, peer review and security regression checks form part of release quality gates.
Backups, restoration testing, incident response procedures and controlled support access are part of the operating model.
During an evaluation, we can provide the current security architecture, data-flow summary, subprocessor information, available control evidence and answers to your security questionnaire.
Request security informationVendorGuard will only claim certifications or independent assurance after they have been completed and can be evidenced. Product evaluations are supported with the most current factual security information available.