Back to VendorBrief

VendorBrief

Security

VendorBrief is built for supplier approval-readiness workflows that require clear access controls, evidence-backed analysis, private storage, and operational accountability.

Report a Concern

Send security concerns to evens.p@elevoraholding.com. Include the affected URL, approximate time, browser or integration context, and a concise description.

Do not include sensitive packet contents, credentials, payment information, or regulated technical data in the initial report.

Current Controls

  • Private Supabase storage and owner-scoped row-level security.
  • Server-side file type and size validation for packet uploads.
  • Company email confirmation before workspace, dashboard, or checkout access.
  • Stripe-hosted billing with signed webhook verification and idempotent processing.
  • Audit logging for sensitive account, upload, delete, checkout, and subscription events.
  • Sentry sanitization to avoid sending document content or secrets into diagnostic events.

Important Limits

VendorBrief does not currently claim SOC 2, ISO 27001, FedRAMP, CMMC certification, ITAR authorization, EAR authorization, or buyer approval authority. None of the handling described below changes that.

Documents carrying export-control, ITAR, EAR/ECCN, CUI or limited-distribution markings are accepted and analysed in restricted mode: the document text is extracted on VendorBrief's own servers and only that text is sent to our AI sub-processor. The original file is never uploaded and no copy of it is created there. Documents carrying classified markings are refused outright, before anything is transmitted.

Restricted mode reduces what leaves our infrastructure; it does not make VendorBrief authorized for controlled data, and it does not analyse page images, so findings that depend on layout may be missed. Whether this handling satisfies your obligations under a specific export classification, prime flow-down or contract is your determination, not ours.