Vendor Security Policy

Version 1.0Effective July 20, 2026Last reviewed July 20, 2026

Third-party vendor and subprocessor security requirements.

Vendor risk assessments

Vendors that process customer data undergo security assessment proportional to risk before onboarding.

Third-party security reviews

High-risk vendors are reviewed annually. Questionnaires, certifications, and audit reports are evaluated where available.

Contract requirements

Contracts include confidentiality, data protection, breach notification, and right-to-audit clauses where appropriate.

Data processing

Subprocessors are documented. Customers are notified of material subprocessor changes per agreement terms.

Ongoing monitoring

Vendor security posture is re-evaluated upon material service changes or reported incidents.