Back to VendorBrief

VendorBrief

Security

VendorBrief is built for supplier approval-readiness workflows that require clear access controls, evidence-backed analysis, private storage, and operational accountability.

Report a Concern

Send security concerns to evens.p@elevoraholding.com. Include the affected URL, approximate time, browser or integration context, and a concise description.

Do not include sensitive packet contents, credentials, payment information, or regulated technical data in the initial report.

Current Controls

  • Private Supabase storage and owner-scoped row-level security.
  • Server-side file type and size validation for packet uploads.
  • Company email confirmation before workspace, dashboard, or checkout access.
  • Stripe-hosted billing with signed webhook verification and idempotent processing.
  • Audit logging for sensitive account, upload, delete, checkout, and subscription events.
  • Sentry sanitization to avoid sending document content or secrets into diagnostic events.

Important Limits

VendorBrief does not currently claim SOC 2, ISO 27001, FedRAMP, CMMC certification, ITAR authorization, EAR authorization, or buyer approval authority. Do not upload controlled data unless Elevora has separately confirmed in writing that the service is authorized for that data.