SECURITY & DATA FAQ
Ask us the hard ones.
60 questions security teams, procurement, and legal ask us, answered with numbers, including a whole section on what we have not built. For the architecture itself, start with the security overview, or forward the review package to your security team.
Validated on arrival
Type allowlist, 40 MB cap, byte-signature check.
Isolated in your tenant
Row-level security and private storage, enforced by the database.
Every touch logged
Views and downloads, yours and ours, in an audit trail you can read.
Deleted for real
Your retention policy, your export, and a hard delete that removes rows and files, with a certificate.
ON THIS PAGE
- 01Architecture and tenant isolation5
- 02Identity and access9
- 03Data lifecycle, upload to deletion7
- 04AI and model data flow5
- 05Benchmarks and data anonymity3
- 06Integrations and API4
- 07Monitoring, audit, and incident response7
- 08Infrastructure and subprocessors5
- 09Compliance and legal6
- 10Product-specific questions4
- 11What we do not have yet5
01 ARCHITECTURE AND TENANT ISOLATION
How is tenant isolation actually enforced?
What happens if there is a bug in your application code?
How do you prove isolation keeps working as you ship?
Do customers share a database?
Are files isolated the same way as database rows?
02 IDENTITY AND ACCESS
What multi-factor authentication do you support?
Do you support single sign-on?
Do you support SCIM provisioning?
What are the password rules?
What are the session lifetimes and session controls?
Can we restrict access to our corporate network?
How do roles and per-contract access work?
Can a customer account become a platform admin?
How are API keys and SCIM tokens protected?
03 DATA LIFECYCLE, UPLOAD TO DELETION
What is validated when a file is uploaded?
How do file downloads work?
How long do you retain our data?
What happens when we delete a contract?
What happens when we delete our whole organization?
Can we export everything we have put in, including the files?
What happens at the end of our contract with you?
04 AI AND MODEL DATA FLOW
When does AI touch our documents?
What exactly leaves your platform, and to whom?
Is our data used to train AI models?
Are AI prompts and outputs logged and attributable?
How do we know an AI answer is grounded and not invented?
05 BENCHMARKS AND DATA ANONYMITY
What goes into the benchmark pool from our contracts?
Could another customer identify us from a benchmark?
Is our pricing visible to other customers?
06 INTEGRATIONS AND API
How are integration and connector credentials stored?
How is inbound email and webhook traffic authenticated?
Are your outbound webhooks signed?
How is the API rate limited?
07 MONITORING, AUDIT, AND INCIDENT RESPONSE
What does an audit event contain?
Is VendorBenchmark staff access logged too?
Can we export the audit history?
Can we stream audit events to our SIEM?
Do you detect and alert on unusual activity?
What is the Security Center?
Have you had a breach, and what is your incident commitment?
08 INFRASTRUCTURE AND SUBPROCESSORS
Where does the platform run, and how is the edge hardened?
Where is our data located?
How is data encrypted, and who manages the keys?
Who are your subprocessors, and where do we track changes?
What is your backup posture?
09 COMPLIANCE AND LEGAL
What is your SOC 2 status?
Where are you on GDPR and CCPA?
How do we execute your DPA?
How do we get your policies and questionnaire answers?
How do we report a vulnerability?
How do you handle law enforcement and government requests?
10 PRODUCT-SPECIFIC QUESTIONS
Who at VendorBenchmark can access our contracts?
How do you secure your own staff?
How do you secure your development process?
What guards external sharing of reports?
11 WHAT WE DO NOT HAVE YET
Do you have a third-party penetration test?
Are you ISO 27001 certified?
Do you support customer-managed keys (BYOK)?
Do you offer EU data residency?
Do you support passkeys or WebAuthn?
Still have questions?
Three ways forward. Email the security owner directly at info@vendorbenchmark.com, request the NDA document room for the policy set and the pre-completed questionnaire, or book the architecture walkthrough and we demonstrate the failing cross-tenant read live.
A question we didn’t answer? Ask it.
Send your security questionnaire. We answer all of it, and we demonstrate the isolation model live.