Trust Center
Security you can verify
The base platform needs nothing from you but vendor domains — no agents, no log access, no credentials. This page sets out exactly what we touch, how the optional Discovery module handles data, where that data lives, and how to run us through your own security review.
1. What we touch, and what we don't
Continuous ratings, breach alerts, impersonation monitoring, fourth-party detection and NIS2/DORA compliance all run from vendor domains alone.
| What | Do we get it? | Detail |
|---|---|---|
| Vendor domains | Yes | You provide them. Everything in the base platform is measured from these, from the public internet. |
| Your logs | No | We never receive your logs. The optional Discovery module reads identity-provider events in memory and stores none of them. |
| Your credentials | No | No passwords, no API keys into your environment. Discovery uses read-only OAuth you can revoke at any time. |
| Your employees' identities | No | Discovery counts users per app. VendorBreach shows how many people use an app, not who. |
| Software on your endpoints | No | Nothing to install. There is no agent, no browser extension and no endpoint software. |
2. Discovery data handling
Discovery is the one optional module that looks inward. You switch it on yourself, and it only ever requests read-only scopes. Read-only. Raw sign-in, consent and audit events are processed in memory and are not stored. We keep the derived app inventory, first and last seen dates, user counts, the scopes each third-party app was granted, and risk flags. Disconnecting a source is one click, and you can ask us to delete the derived data at the same time.
Okta
SSO'd applications only. Apps your people sign into with a password outside Okta are invisible to this source.
openidConfirms the connection is authenticated.profileName of the admin who authorised the connection.emailEmail of the admin who authorised the connection.okta.apps.readList of applications configured in your Okta org.okta.users.readUser records, used only to produce per-app user counts.okta.logs.readSystem log events, read in memory to derive first/last seen. Not stored.
Microsoft Entra ID
OAuth consents and SSO'd apps. Password-only websites and locally installed software are invisible to this source.
openidConfirms the connection is authenticated.profileName of the admin who authorised the connection.emailEmail of the admin who authorised the connection.offline_accessLets the scheduled sync refresh without asking an admin to sign in again.User.ReadProfile of the admin who authorised the connection.Application.Read.AllRegistered applications and service principals in your tenant.Directory.Read.AllDirectory objects, used only to produce per-app user counts.AuditLog.Read.AllSign-in and consent events, read in memory to derive first/last seen. Not stored.
Google Workspace
OAuth consents and SSO'd apps. Password-only websites are invisible to this source.
openidConfirms the connection is authenticated.profileName of the admin who authorised the connection.emailEmail of the admin who authorised the connection.https://www.googleapis.com/auth/admin.directory.user.readonlyDirectory users, used only to produce per-app user counts.https://www.googleapis.com/auth/admin.reports.audit.readonlyToken and login audit reports, read in memory to derive first/last seen. Not stored.
PingOne
Applications configured in the PingOne environment you connect.
openidConfirms the connection is authenticated.profileName of the admin who authorised the connection.emailEmail of the admin who authorised the connection.p1:read:userUser records, used only to produce per-app user counts.p1:read:applicationApplications configured in your PingOne environment.
File-based sources
VendorBreach shows how many people use an app, not who.
No screen in VendorBreach shows which named person uses which application. We keep the app inventory, its category, first and last seen dates, a user count, the granted scopes and risk flags — nothing that identifies an individual employee.
3. Data residency
Where your data is actually stored and processed. Regions marked Roadmap do not exist yet and we won't claim otherwise.
Canada
United States
European Union
United Kingdom
4. Legal
Data processing agreement
Our standard DPA is available on request and can be countersigned before you onboard.
Request the DPASub-processors
The full list, with what each one handles and where, is published below on this page.
View sub-processor listPrivacy & terms
How we handle personal data, and the terms your subscription runs under.
SOC 2 Type II
Security overview (PDF)
A one-document summary for your review file. Coming shortly.
Sub-processors
These providers may process customer data on our behalf. We give customers notice before adding a sub-processor that handles personal data. "Country of data residency" is where the data is actually stored and processed — not where the company is headquartered.
| Provider | Country of data residency |
|---|---|
| LovableApplication hosting and platform infrastructure | USA Hosted on US-region infrastructure (CDN edge caching is global). |
| SupabaseManaged Postgres database, authentication, file storage | USA Primary database hosted in AWS US-East-2 (Ohio, USA). |
| StripeSubscription billing and payment processing | USA Global payments processor; EU data handled under Stripe's own transfer safeguards. |
| ResendTransactional and notification email delivery | USA EU sending region available. |
| Google (Gemini via Lovable AI Gateway)AI assessment summaries and questionnaire assistance | USA Prompts are not used to train models. AI features can be disabled per organisation. |
5. Security practices
SOC 2 Type I
Audit underway with an independent firm. Report expected Q4 2026.
Penetration testing
A manual third-party penetration test every six months, plus an automated AI-driven penetration test that runs daily against our own platform.
Encryption
Traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting provider.
Tenant isolation
Postgres row-level security on every table. Each record is stamped with an org_id and access is scoped to your organisation.
Access control
Role-based access with a dedicated roles table, multi-factor authentication on staff accounts, and SAML/OIDC single sign-on for customers.
Backups & retention
Automated weekly exports of your tenant data with an admin-configurable retention window and a documented restore workflow.
Data handling & deletion
Customer data
Backups
Deletion — 48 hours
Report a vulnerability
Email security@vendorbreach.com with steps to reproduce. We acknowledge reports and will keep you updated while we investigate. Our machine-readable policy is published at /.well-known/security.txt. Please give us a reasonable window to remediate before public disclosure.
6. Run us through your security review
Enterprise TPRM teams put every vendor through their own process — including us. Tell us what you need and we'll return the documentation, the completed questionnaire and a named contact.
Request a security reviewNeed our pentest letter, security questionnaire response, or SOC 2 status in writing? Email trust@vendorbreach.com.