Vendavo · Trust Center

Vendavo Trust Center

Trust center

Vendavo publishes a public security posture page at www.vendavo.com/security/ (last updated by Vendavo 11 June 2026) and operates a Trust Center at trustvault.vendavo.com (a Scrut.io tenant, HTTP 200). The certifications below are quoted from the public security page; the Trust Center itself renders client-side and gates its document library behind an access request, so the certification list was taken from the server-rendered security page rather than the Trust Center shell. The automated trust-center probe missed this because Vendavo uses the non-standard `trustvault.` subdomain rather than `trust.`.

Vendavo maintains a public trust center documenting ISO/IEC 27001:2022, SOC 1 Type 2, SOC 2 Type 2, CSA STAR Level 1 (CAIQ self-assessment), and ISO 22301 compliance.

CompanyEnterprisePricingCPQQuotingRebatesB2BCommercial OptimizationMargin OptimizationAI
Trust center: https://trustvault.vendavo.com/

Certifications & Compliance

ISO/IEC 27001:2022SOC 1 Type 2SOC 2 Type 2CSA STAR Level 1 (CAIQ self-assessment)ISO 22301

Source

Trust Center

vendavo-trust-center.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: false
source: https://www.vendavo.com/security/
url: https://trustvault.vendavo.com/
description: >-
  Vendavo publishes a public security posture page at www.vendavo.com/security/ (last
  updated by Vendavo 11 June 2026) and operates a Trust Center at
  trustvault.vendavo.com (a Scrut.io tenant, HTTP 200). The certifications below are
  quoted from the public security page; the Trust Center itself renders client-side and
  gates its document library behind an access request, so the certification list was
  taken from the server-rendered security page rather than the Trust Center shell. The
  automated trust-center probe missed this because Vendavo uses the non-standard
  `trustvault.` subdomain rather than `trust.<domain>`.
trust_center:
  url: https://trustvault.vendavo.com/
  platform: Scrut.io
  http_status: 200
  document_access: request-access
  note: >-
    "Trust Center – Visit our Trust Center to learn about our security posture and
    request access to documentation" (www.vendavo.com/security/). The page is a
    client-rendered Next.js shell; no certification data is present in the served HTML.
certifications:
- name: ISO/IEC 27001:2022
  status: certified
  cadence: annual
  note: >-
    "Vendavo maintains certification to the international standard to manage information
    security." ISMS is built on ISO 27001.
- name: SOC 1 Type 2
  status: attested
  cadence: annual
  availability: on request via Trust Center
  note: '"Vendavo conducts annual audits to ensure controls over financial reporting."'
- name: SOC 2 Type 2
  status: attested
  cadence: annual
  availability: on request via Trust Center
  trust_services_criteria: [Security, Availability, Confidentiality, Processing Integrity]
  note: >-
    "Vendavo conducts annual audits to ensure control and management of customer data,
    covering the Security, Availability, Confidentiality and Processing Integrity Trust
    Services Criteria."
- name: CSA STAR Level 1 (CAIQ self-assessment)
  status: self-assessed
  registry: https://cloudsecurityalliance.org/star/registry/vendavo/
  registry_http_status: 200
  note: >-
    "Vendavo has published our completed CSA Consensus Assessments Initiative
    Questionnaire (CAIQ) self-assessment in the CSA STAR Registry."
- name: ISO 22301
  status: aligned
  note: >-
    Not a certification claim — "our business continuity program is aligned with the
    international standard ISO 22301."
privacy_regimes:
- {name: EU GDPR, claim: enables customer compliance}
- {name: UK GDPR, claim: enables customer compliance}
- {name: California CPRA, claim: enables customer compliance}
security_practices:
- Independent penetration tests, static and dynamic testing, security design and code reviews.
- Regular internal and external vulnerability scans; systematic patch management program.
- Encryption at rest and in transit; customer data segmentation in multi-tenant applications.
- Fine-grained RBAC/ABAC; SSO integration with customer identity management systems.
- EDR/XDR with 24x7x365 Security Operations oversight; DDoS protection via firewalls, load balancers, WAF.
- ISMS governed by a Security & Compliance Council chaired by the CISO, meeting bimonthly.
vulnerability_disclosure:
  published: false
  note: >-
    No responsible-disclosure or vulnerability-reporting policy, no bug-bounty program
    and no security contact address are published. /.well-known/security.txt returns 404
    on every Vendavo host, and neither the security page, the privacy notice nor the
    contractor security policy names a security@ address. No `VulnerabilityDisclosure`
    artifact and no `Security` pointer are emitted — there is nothing to point at.
docs:
- https://www.vendavo.com/security/
- https://www.vendavo.com/contractor-security-policy/
- https://cloudsecurityalliance.org/star/registry/vendavo/
evidence:
- {url: 'https://www.vendavo.com/security/', status: 200, keywords: [iso 27001:2022, soc 1 type 2, soc 2 type 2, csa star, caiq, iso 22301, gdpr, cpra]}
- {url: 'https://trustvault.vendavo.com/', status: 200, note: 'Scrut.io Trust Center; client-rendered shell, title "Trust Vault"'}
- {url: 'https://cloudsecurityalliance.org/star/registry/vendavo/', status: 200, note: 'page title "STAR Registry Entries for Vendavo Inc."'}
- {url: 'https://www.vendavo.com/.well-known/security.txt', status: 404}