Security & privacy

VendorReadyHQ holds insurance certificates, licences and tax forms belonging to your vendors. Here is exactly how that data is protected — and what we do not claim.

Authentication

Accounts sign in with email and password through a managed authentication service. Sessions are issued as short-lived tokens and every application route behind sign-in checks the session before rendering.

Workspace isolation

Every vendor, document, request and report row belongs to a workspace. Access rules are enforced in the database itself, not only in the interface, so a request for another workspace's data returns nothing even if it is crafted by hand.

Private document storage

Uploaded documents live in a private storage bucket that is not publicly listable. Files are served through time-limited signed links generated for a signed-in member of the owning workspace.

Roles and permissions

Workspaces have owners and members. Only owners can invite people, change roles, remove members and manage billing. A workspace always keeps at least one owner.

Audit and activity history

Vendor changes, document updates, requests, follow-ups and automated jobs are recorded with a timestamp so your team can see what happened and when.

Billing security

Card details never reach VendorReadyHQ. Checkout and the billing portal are hosted by Paddle, our Merchant of Record. Subscription changes arrive as signature-verified webhooks that are rejected if the signature, environment or ordering does not check out.

Data handling

We store the vendor and document data you enter, the account details needed to run your workspace, and operational logs. Vendor upload links are single-purpose tokens that only permit uploading to the vendor they were issued for.

What we do not claim

VendorReadyHQ does not hold SOC 2, ISO 27001, PCI or HIPAA certification, and we make no GDPR certification claim. We describe the controls we actually operate, nothing more. VendorReadyHQ also does not determine whether a vendor is legally compliant, adequately insured or licensed — it organizes and monitors the requirements you define. Review documents with your own legal, insurance and risk advisers before approving a vendor.

Reporting a security issue

Email support@vendorreadyhq.com with the details and we will respond. VendorReadyHQ is operated by ASRE HOLDINGS.