Trust and security

Where your data lives, who can reach it, what the evidence is

The questions we ask your vendors on your behalf, answered here for VendorManager itself — including what we do not have yet.

Hosting and data locationDatabase and file storage in the EU (Supabase, Frankfurt region); application hosted on Netlify. No transfer of production data outside the EEA.
Separation between clientsOne workspace per organisation; row-level security (RLS) on every table in the database, including for the VendorManager consultant. Files sit in a private bucket and are reachable only through an authenticated download.
AccessInvite-only. Sign-in is passwordless, with a one-time code by e-mail, or through your own identity provider (Microsoft Entra ID via SAML; SCIM provisioning on Assurance). Roles carry mandates; our consultant's access is visible and logged in your audit trail.
SessionsA session expires after eight hours without activity, and in any case after seven days. This is tracked server-side, so clearing cookies does not extend it.
Continuity of serviceThe service is delivered by a named vendor manager, with a contracted stand-in for absences longer than five working days. The stand-in is activated within two working days, is bound by the same confidentiality and processing terms, and is listed as a sub-processor in your data processing agreement. We rehearse the handover annually.
Audit trailEvery action — ours included — is written to an append-only log with a hash chain, so its integrity can be verified. Exportable as CSV.
Your data stays yoursA full export (register, workflows, documents, audit trail) at any moment, in one click. On termination: export first, then deletion within 30 days, confirmed in writing.
AI and text recognitionUsed to propose fields and interpretations; a human always confirms. Wherever AI was used, it says so next to the result (AI Act art. 50). No models are trained on your data.
Sub-processorsSupabase (database, storage, authentication), Netlify (hosting), Resend (transactional e-mail), optionally Signhost (e-signature) and Anthropic (AI suggestions). Changes are announced in advance.
Data processing agreementA standard part of the service agreement; available up front on request.
Security programmeEncryption in transit and at rest, security headers, secrets kept out of the code, daily backups with restores tested.

What happens if something happens to your vendor manager?

That is the fair question when you outsource management to a small firm, and it deserves a concrete answer rather than reassurance. Ours has three parts.

A contracted stand-in. An independent vendor management professional with comparable experience, contracted in advance, bound by the same confidentiality terms and named in your data processing agreement. For an absence longer than five working days we activate them within two working days and tell you.

No handover period needed. The whole file lives in the platform: register, running workflows, correspondence, decisions and the audit trail. Nothing sits in one head or one mailbox. So someone else can pick up tomorrow where we left off today — and we rehearse that handover every year.

You never depend on us for your own data. A full export of register, workflows, documents and audit trail is one action, at any moment. If the engagement ends, the work stays with you.

In the event of a permanent absence you may terminate early on one month’s notice, with nothing payable for the remaining term. That is written into our service agreement.

What we do not have yet

We hold no external certification (ISO 27001 or SOC 2) and no third-party penetration test report. ISO 27001 certification is planned within twelve months; until then we share our policy and the latest external review on request. We would rather say so than paper over it — it is exactly the question we put to your vendors on your behalf.

Need a questionnaire completed?

If your security or procurement team sends out a standard security questionnaire, send it over; we will complete it and attach the supporting documents. Mail bob.goosen@digitalsourcing.nl or use the contact form.

This page is updated with every release of the platform. See also our privacy statement.