Trust Center

    Security you can verify

    The base platform needs nothing from you but vendor domains — no agents, no log access, no credentials. This page sets out exactly what we touch, how the optional Discovery module handles data, where that data lives, and how to run us through your own security review.

    1. What we touch, and what we don't

    Continuous ratings, breach alerts, impersonation monitoring, fourth-party detection and NIS2/DORA compliance all run from vendor domains alone.

    WhatDo we get it?Detail
    Vendor domains YesYou provide them. Everything in the base platform is measured from these, from the public internet.
    Your logs NoWe never receive your logs. The optional Discovery module reads identity-provider events in memory and stores none of them.
    Your credentials NoNo passwords, no API keys into your environment. Discovery uses read-only OAuth you can revoke at any time.
    Your employees' identities NoDiscovery counts users per app. VendorBreach shows how many people use an app, not who.
    Software on your endpoints NoNothing to install. There is no agent, no browser extension and no endpoint software.

    2. Discovery data handling

    Discovery is the one optional module that looks inward. You switch it on yourself, and it only ever requests read-only scopes. Read-only. Raw sign-in, consent and audit events are processed in memory and are not stored. We keep the derived app inventory, first and last seen dates, user counts, the scopes each third-party app was granted, and risk flags. Disconnecting a source is one click, and you can ask us to delete the derived data at the same time.

    Okta

    SSO'd applications only. Apps your people sign into with a password outside Okta are invisible to this source.

    • openidConfirms the connection is authenticated.
    • profileName of the admin who authorised the connection.
    • emailEmail of the admin who authorised the connection.
    • okta.apps.readList of applications configured in your Okta org.
    • okta.users.readUser records, used only to produce per-app user counts.
    • okta.logs.readSystem log events, read in memory to derive first/last seen. Not stored.

    Microsoft Entra ID

    OAuth consents and SSO'd apps. Password-only websites and locally installed software are invisible to this source.

    • openidConfirms the connection is authenticated.
    • profileName of the admin who authorised the connection.
    • emailEmail of the admin who authorised the connection.
    • offline_accessLets the scheduled sync refresh without asking an admin to sign in again.
    • User.ReadProfile of the admin who authorised the connection.
    • Application.Read.AllRegistered applications and service principals in your tenant.
    • Directory.Read.AllDirectory objects, used only to produce per-app user counts.
    • AuditLog.Read.AllSign-in and consent events, read in memory to derive first/last seen. Not stored.

    Google Workspace

    OAuth consents and SSO'd apps. Password-only websites are invisible to this source.

    • openidConfirms the connection is authenticated.
    • profileName of the admin who authorised the connection.
    • emailEmail of the admin who authorised the connection.
    • https://www.googleapis.com/auth/admin.directory.user.readonlyDirectory users, used only to produce per-app user counts.
    • https://www.googleapis.com/auth/admin.reports.audit.readonlyToken and login audit reports, read in memory to derive first/last seen. Not stored.

    PingOne

    Applications configured in the PingOne environment you connect.

    • openidConfirms the connection is authenticated.
    • profileName of the admin who authorised the connection.
    • emailEmail of the admin who authorised the connection.
    • p1:read:userUser records, used only to produce per-app user counts.
    • p1:read:applicationApplications configured in your PingOne environment.

    File-based sources

    Log or SaaS export (CSV)Whatever the export contains. Okta, Entra and Google Workspace exports are recognised, as is a generic SaaS usage list. Parsed in your browser — the file is never uploaded.
    Finance / expense exportPaid apps only. Free-tier and personal-account signups won't appear in a spend export.

    VendorBreach shows how many people use an app, not who.

    No screen in VendorBreach shows which named person uses which application. We keep the app inventory, its category, first and last seen dates, a user count, the granted scopes and risk flags — nothing that identifies an individual employee.

    3. Data residency

    Where your data is actually stored and processed. Regions marked Roadmap do not exist yet and we won't claim otherwise.

    Canada

    Available
    Default home region for new tenants; primary data store.

    United States

    Available
    Hosting and most enrichment providers operate from US regions.

    European Union

    Roadmap
    No EU data store exists yet. We will not claim one until it does.

    United Kingdom

    Roadmap
    Not available today.

    Data processing agreement

    Our standard DPA is available on request and can be countersigned before you onboard.

    Request the DPA

    Sub-processors

    The full list, with what each one handles and where, is published below on this page.

    View sub-processor list

    Privacy & terms

    How we handle personal data, and the terms your subscription runs under.

    SOC 2 Type II

    In progress. Our Type I audit is underway with an independent firm; we are not claiming a Type II report until one is issued.

    Security overview (PDF)

    A one-document summary for your review file. Coming shortly.

    Sub-processors

    These providers may process customer data on our behalf. We give customers notice before adding a sub-processor that handles personal data. "Country of data residency" is where the data is actually stored and processed — not where the company is headquartered.

    ProviderCountry of data residency
    LovableApplication hosting and platform infrastructure
    USA
    Hosted on US-region infrastructure (CDN edge caching is global).
    SupabaseManaged Postgres database, authentication, file storage
    USA
    Primary database hosted in AWS US-East-2 (Ohio, USA).
    StripeSubscription billing and payment processing
    USA
    Global payments processor; EU data handled under Stripe's own transfer safeguards.
    ResendTransactional and notification email delivery
    USA
    EU sending region available.
    Google (Gemini via Lovable AI Gateway)AI assessment summaries and questionnaire assistance
    USA
    Prompts are not used to train models. AI features can be disabled per organisation.

    5. Security practices

    SOC 2 Type I

    In progress

    Audit underway with an independent firm. Report expected Q4 2026.

    Penetration testing

    6-monthly + daily

    A manual third-party penetration test every six months, plus an automated AI-driven penetration test that runs daily against our own platform.

    Encryption

    Always on

    Traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting provider.

    Tenant isolation

    Enforced

    Postgres row-level security on every table. Each record is stamped with an org_id and access is scoped to your organisation.

    Access control

    Built in

    Role-based access with a dedicated roles table, multi-factor authentication on staff accounts, and SAML/OIDC single sign-on for customers.

    Backups & retention

    Weekly

    Automated weekly exports of your tenant data with an admin-configurable retention window and a documented restore workflow.

    Data handling & deletion

    Customer data

    Vendor records, assessments, findings and evidence are retained for the life of your subscription and remain scoped to your organisation.

    Backups

    Weekly tenant exports are stored with an admin-configurable retention window; older backup files are pruned automatically once that window passes.

    Deletion — 48 hours

    Account deletion is available in-app and removes your organisation's records. A written deletion request — including Discovery data — is actioned within 48 hours.

    Report a vulnerability

    Email security@vendorbreach.com with steps to reproduce. We acknowledge reports and will keep you updated while we investigate. Our machine-readable policy is published at /.well-known/security.txt. Please give us a reasonable window to remediate before public disclosure.

    6. Run us through your security review

    Enterprise TPRM teams put every vendor through their own process — including us. Tell us what you need and we'll return the documentation, the completed questionnaire and a named contact.

    Request a security review

    Need our pentest letter, security questionnaire response, or SOC 2 status in writing? Email trust@vendorbreach.com.