Security
Security practices at Vendrsec
We build a vulnerability management tool — which means our own security posture gets scrutinized by the people evaluating us. This page describes what data we process, what controls we’ve implemented, and how to report a finding to us.
Data Handling
What data we handle
Vendrsec processes CVE IDs, asset identifiers (FQDNs, IPs, cloud ARNs), CVSS scores, and finding metadata pulled from your scanner APIs. We do not process exploit code, raw vulnerability payloads, authentication credentials, or any application data from your production systems. Scanner API tokens are stored encrypted and scoped read-only — we do not request write permissions to your scanner.
What we store
- CVE identifiers and CVSS scores
- Asset identifiers (FQDN, IP, ARN)
- Vendrsec Risk Scores and history
- Remediation ticket records
What we never store
- Exploit code or payloads
- Raw scanner API credentials
- Production data or PII from your systems
- Source code or application internals
Controls
Controls we’ve implemented
SOC 2 controls were designed into the architecture from the initial build — not added as a compliance retrofit after customers asked. The audit is in progress. Controls are live. The pre-audit controls summary is available on request under NDA for security-conscious evaluators.
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- US-region data residency by default
- API token rotation and least-privilege scoping — read-only access to your scanner APIs
- SOC 2 controls designed into the architecture — audit in progress, report available on request under NDA
- Access logging and anomaly detection on all data access patterns
Disclosure
Responsible disclosure
Found a security issue in Vendrsec? We take it seriously — we sell to security teams, so our own posture is always on display. We follow coordinated disclosure and will not pursue legal action against good-faith security researchers.
Report a vulnerability
Email [email protected] with a description of the issue and steps to reproduce. We commit to acknowledgment within 24 hours and remediation timelines communicated within 5 business days.
We ask for reasonable disclosure timelines (typically 90 days) and will coordinate public disclosure with you. Vendrsec does not use legal mechanisms against good-faith researchers who follow this process.