About us

    An independent vendor risk platform, built in Halifax

    A company that sells vendor risk management should not itself be an unknown-origin vendor. Here is who we are, where we are, and which laws we answer to.

    Where we are based

    Jurisdiction: Canada

    VendorBreach is based in Halifax, Nova Scotia, Canada. The company is Canadian-operated and subject to Canadian federal privacy law — the Personal Information Protection and Electronic Documents Act (PIPEDA) — as well as applicable Nova Scotia provincial law.

    Details of the providers that process customer data on our behalf, and the country each one stores data in, are published on our Trust Center.

    Why we built VendorBreach

    Third-party breaches are now one of the most common ways an organisation gets compromised, yet the tools for managing vendor risk were built for large enterprises with dedicated risk teams and six-figure budgets. Everyone else was left with a spreadsheet, an annual questionnaire nobody read, and no way of knowing when a supplier's security actually changed.

    VendorBreach was created to close that gap: continuous, evidence-based vendor monitoring with scoring you can explain to an auditor, questionnaires and evidence collection that vendors will actually complete, and pricing that a small security team, a municipality or a managed service provider can justify.

    We stay deliberately independent. We publish our own security posture, our own subprocessors and our own data residency, and we expect our customers to hold us to the same standard we help them apply to everyone else.

    What we stand for

    Independent

    We are not owned by a scanner vendor, a consultancy or an insurer. Our ratings are not for sale and vendors cannot pay to change a score.

    Affordable by design

    Third-party risk tooling has traditionally been priced for enterprise budgets. We build for the security teams, MSPs and small organisations who were priced out.

    Transparent

    Every score is explainable, every subprocessor is published, and where we are based is on this page rather than buried in a contract.

    Evaluating us as a vendor?

    Ask for our security documentation, or read the Trust Center first.