SECURITY REVIEW PACKAGE

Everything your security team needs, one link.

This page is written for the reviewer, not the buyer. It lays out the reading order, links every artifact, and lists three verifications you can run yourself in a trial tenant. Nothing on it is aspirational: every claim is implemented, and anything we have not built is listed as not built.

START HERE

The review path, in order.

Seven artifacts, sequenced so each one answers the questions the previous one raises. Everything except the document room is public, no NDA and no sales call required to start.

  1. 1
    The security overview

    The architecture, the enforced numbers, the AI data flow, and the claim ladder. Ten minutes, and it includes what we have not built.

  2. 2
    The full security FAQ

    Sixty questions in eleven sections, from the audit event schema to key management, answered with numbers.

  3. 3
    The data processing agreement

    Public, not gated behind sales. Check it against the AI data flow and deletion mechanics stated on the security page.

  4. 4
    The subprocessor list

    Five subprocessors with roles: Vercel, Supabase, Anthropic, Resend, Upstash. All data hosted in the US today.

  5. 5
    The terms of service

    The commercial terms your legal team will read anyway, public for the same reason the DPA is.

  6. 6
    The NDA document room

    The policy set, a pre-completed security questionnaire, and SOC 2 evidence when the auditor issues it. Token-scoped links, NDA click-through, every open audit-logged.

  7. 7
    Responsible disclosure and security.txt

    Acknowledgment within 3 business days, safe harbor for good-faith research, published at /.well-known/security.txt.

THE PACKAGE

Every artifact, and what to check in it.

Each card says what the artifact is and what a reviewer should look for. The last three are in-product: the platform itself is part of the package.

Security overview

The mechanism-by-mechanism page: database-enforced isolation across roughly 200 tables, 60-second signed downloads, the identity stack, and the incident commitment.

Check the claim ladder: anything marked Implemented is in the code, and the Not yet column is deliberately public.

Security FAQ

The long-form companion, organized for a reviewer: architecture, identity, lifecycle, AI, benchmarks, integrations, monitoring, infrastructure, compliance, and the not-yet list.

Check that every answer states a number or names a gap. None of them hedges.

Data processing agreement

Our standard DPA, public. GDPR deletion is a live product path, not a ticket queue, and the records of processing are being finalized with counsel.

Check that the DPA's processing description matches the AI data flow and subprocessor list. It should, they are maintained together.

Subprocessor list

Vercel and Supabase run the infrastructure, both SOC 2 Type II audited. Anthropic runs AI inference, Resend sends email, Upstash backs rate limiting.

Check the roles: no analytics vendors, no ad networks, and no AI vendor other than Anthropic touches customer data.

Terms of service

The commercial terms, public alongside the DPA so legal review can start without a sales call.

Check the data ownership and termination language against the export and deletion mechanics in the FAQ.

NDA document room

The policy set, a pre-completed security questionnaire, and the SOC 2 report when issued. Access links are token-scoped, gated by an NDA click-through, and every open is audit-logged.

Start with the pre-completed questionnaire: it answers the standard questions up front, so your own questionnaire becomes a diff, not a project.

Security Center, in the product

A live posture page inside the app under Settings, Security (the Posture tab): your org's MFA coverage, the audit export, and the SIEM webhook setup. Requires a login, which a trial tenant provides.

Check that what this page shows matches what the marketing pages claim. That is what it is for.

Open Security Center

Requires a signed-in account.

Audit trail, exportable

Every view, download, create, update, and delete is logged with actor, action, entity, org, IP, and user agent. Analyst access is logged identically. Owners export the full history as CSV.

Check your own trial activity in the export: your uploads, views, and downloads should all be there, including ours.

Export from Security Center

Requires a signed-in account.

SIEM streaming

Signed batches of audit events push to your SIEM every 15 minutes, cursor-tracked so nothing is skipped. Setup lives in the Security Center.

Check the signatures and the cursor: replay a batch and verify your systems can authenticate us the way we authenticate them.

Set up in Security Center

Requires a signed-in account.

VERIFY, DON’T TRUST

Three things you can verify live in a trial tenant.

A security page is a set of claims. A trial tenant is a lab. These three checks take about thirty minutes and test the controls that matter most: isolation, accountability, and deletion.

Verification 1

Run the isolation test yourself

Create two trial organizations. Upload a contract to one, then try to read it from the other organization's session. The attempt fails at the database: the API returns row-level denials, not application errors, because Postgres row-level security refuses the rows before any application code runs. This is the same check our 24 CI isolation suites run on every change.

Verification 2

Watch your own audit stream

Subscribe a webhook from the Security Center and act in your trial tenant: view a contract, download a file, change a permission. Signed, cursor-tracked batches arrive within 15 minutes carrying actor, action, entity, org, IP, and user agent for everything you just did.

Verification 3

Test deletion end to end

Delete a contract and confirm the database rows and the stored files are gone, not flagged. Then download the deletion certificate: every contract or organization deletion writes a durable, timestamped certificate your org can keep for its own records.

OUR SIDE OF THE REVIEW

What we will do in your review.

  • We complete your security questionnaire, whichever framework it follows, and cite the mechanism behind each answer.
  • We walk your team through the architecture live, from the row-level security policies to the signed URL path.
  • We demonstrate the failing cross-tenant read in a live session, not on a slide.
  • We sign your NDA or you use ours, whichever moves faster.
  • We answer within the SLAs we publish: vulnerability reports acknowledged within 3 business days, and if an incident ever affects your data, direct notification within 72 hours of confirmation followed by a written post-mortem.

Security is owned by Fredrik Filipsson, founder. Reach the security team at info@vendorbenchmark.com.

THE HONEST GAPS

What we have not built, before you ask.

Every reviewer finds the gaps eventually. Listing them up front saves you the hunt and tells you our Implemented column means what it says. The full picture lives in the claim ladder on the security page, including what we have not built.

Third-party penetration test

Not yet. The first engagement is being scheduled; the report will land in the NDA document room.

ISO 27001

Not started. SOC 2 Type II comes first: controls implemented, evidence collection underway.

Customer-managed keys (BYOK)

Not built. Encryption keys are provider-managed today.

EU data residency

Not built. All data is hosted in the US today.

Passkeys / WebAuthn

Not built. TOTP is the second factor today.

Everything else

The Implemented and In progress columns, with dates and evidence, live on the security overview.

New this month: organization owners can set an IP allowlist (CIDR) and a session policy (maximum session age, idle timeout) under Settings, and every contract or organization deletion now writes a durable, timestamped deletion certificate your org can download.

Details in the FAQ

Reviewer? We built this page for you.

Send the questionnaire, book the architecture walkthrough, or get a trial tenant and run the three verifications yourself.