Security & data handling
What we hold, where it sits, and who can reach it.
Every sentence on this page describes a practice we will actually operate on day one. There are no certifications claimed here, because we don't hold any yet — when that changes, this page changes.
What we hold
Vendor documents you send us or that vendors and their agencies send on your behalf, the requirement list you define, contact records for vendors and agencies, and the correspondence log behind every status. We ask for the minimum needed to run the workflow.
Encryption
Documents and records are encrypted in transit and at rest by the platforms we operate on. We do not run our own storage infrastructure and we do not keep client documents on personal devices.
Access control
Least privilege, enforced by role: a coordinator can reach the accounts they work on and nothing else. Access is provisioned when someone is assigned to your account and removed when they are not. Owner-level access exists for administration and is used for administration.
Client separation
Each client's records are logically separated. Nothing about your vendor list, your requirement matrix, or your correspondence is visible from another client's workspace.
How documents move
We avoid emailing sensitive documents when a controlled link will do. Where email is unavoidable — because a vendor's agency will only send a certificate that way — the document is filed into your record and the correspondence is logged.
Retention and export
Your records are yours. Export provisions are written into the agreement, including the format and the turnaround. If we part ways, you leave with a complete, organized file rather than a support ticket.
Subcontractors
Coordinator coverage is delivered by contracted personnel working under confidentiality terms and the same access controls. We will tell you who is assigned to your account, and we will tell you if that changes.
If something goes wrong
We commit to notifying you promptly on discovering unauthorized access to your records, with what we know, what we don't yet know, and what we're doing about it. We would rather send an early, incomplete notice than a tidy, late one.
What we are not claiming
- No SOC 2, ISO 27001, or HIPAA certification. If your procurement process requires one today, we are not your vendor yet.
- No representation that document administration reduces your organization's exposure. That is a question for your broker and your counsel.
- No penetration-test report, because we have not commissioned one.
Start with the assessment, or start with the report.
Every engagement starts with a paid Vendor Workflow Assessment. If you'd rather see the work product first, the sample monthly report is a full specimen and takes a short form.