Security & privacy
VendorReadyHQ holds insurance certificates, licences and tax forms belonging to your vendors. Here is exactly how that data is protected — and what we do not claim.
Authentication
Accounts sign in with email and password through a managed authentication service. Sessions are issued as short-lived tokens and every application route behind sign-in checks the session before rendering.
Workspace isolation
Every vendor, document, request and report row belongs to a workspace. Access rules are enforced in the database itself, not only in the interface, so a request for another workspace's data returns nothing even if it is crafted by hand.
Private document storage
Uploaded documents live in a private storage bucket that is not publicly listable. Files are served through time-limited signed links generated for a signed-in member of the owning workspace.
Roles and permissions
Workspaces have owners and members. Only owners can invite people, change roles, remove members and manage billing. A workspace always keeps at least one owner.
Audit and activity history
Vendor changes, document updates, requests, follow-ups and automated jobs are recorded with a timestamp so your team can see what happened and when.
Billing security
Card details never reach VendorReadyHQ. Checkout and the billing portal are hosted by Paddle, our Merchant of Record. Subscription changes arrive as signature-verified webhooks that are rejected if the signature, environment or ordering does not check out.
Data handling
We store the vendor and document data you enter, the account details needed to run your workspace, and operational logs. Vendor upload links are single-purpose tokens that only permit uploading to the vendor they were issued for.
What we do not claim
VendorReadyHQ does not hold SOC 2, ISO 27001, PCI or HIPAA certification, and we make no GDPR certification claim. We describe the controls we actually operate, nothing more. VendorReadyHQ also does not determine whether a vendor is legally compliant, adequately insured or licensed — it organizes and monitors the requirements you define. Review documents with your own legal, insurance and risk advisers before approving a vendor.
Reporting a security issue
Email support@vendorreadyhq.com with the details and we will respond. VendorReadyHQ is operated by ASRE HOLDINGS.