generated: '2026-08-13' method: searched probe: false source: https://www.vendavo.com/security/ url: https://trustvault.vendavo.com/ description: >- Vendavo publishes a public security posture page at www.vendavo.com/security/ (last updated by Vendavo 11 June 2026) and operates a Trust Center at trustvault.vendavo.com (a Scrut.io tenant, HTTP 200). The certifications below are quoted from the public security page; the Trust Center itself renders client-side and gates its document library behind an access request, so the certification list was taken from the server-rendered security page rather than the Trust Center shell. The automated trust-center probe missed this because Vendavo uses the non-standard `trustvault.` subdomain rather than `trust.`. trust_center: url: https://trustvault.vendavo.com/ platform: Scrut.io http_status: 200 document_access: request-access note: >- "Trust Center – Visit our Trust Center to learn about our security posture and request access to documentation" (www.vendavo.com/security/). The page is a client-rendered Next.js shell; no certification data is present in the served HTML. certifications: - name: ISO/IEC 27001:2022 status: certified cadence: annual note: >- "Vendavo maintains certification to the international standard to manage information security." ISMS is built on ISO 27001. - name: SOC 1 Type 2 status: attested cadence: annual availability: on request via Trust Center note: '"Vendavo conducts annual audits to ensure controls over financial reporting."' - name: SOC 2 Type 2 status: attested cadence: annual availability: on request via Trust Center trust_services_criteria: [Security, Availability, Confidentiality, Processing Integrity] note: >- "Vendavo conducts annual audits to ensure control and management of customer data, covering the Security, Availability, Confidentiality and Processing Integrity Trust Services Criteria." - name: CSA STAR Level 1 (CAIQ self-assessment) status: self-assessed registry: https://cloudsecurityalliance.org/star/registry/vendavo/ registry_http_status: 200 note: >- "Vendavo has published our completed CSA Consensus Assessments Initiative Questionnaire (CAIQ) self-assessment in the CSA STAR Registry." - name: ISO 22301 status: aligned note: >- Not a certification claim — "our business continuity program is aligned with the international standard ISO 22301." privacy_regimes: - {name: EU GDPR, claim: enables customer compliance} - {name: UK GDPR, claim: enables customer compliance} - {name: California CPRA, claim: enables customer compliance} security_practices: - Independent penetration tests, static and dynamic testing, security design and code reviews. - Regular internal and external vulnerability scans; systematic patch management program. - Encryption at rest and in transit; customer data segmentation in multi-tenant applications. - Fine-grained RBAC/ABAC; SSO integration with customer identity management systems. - EDR/XDR with 24x7x365 Security Operations oversight; DDoS protection via firewalls, load balancers, WAF. - ISMS governed by a Security & Compliance Council chaired by the CISO, meeting bimonthly. vulnerability_disclosure: published: false note: >- No responsible-disclosure or vulnerability-reporting policy, no bug-bounty program and no security contact address are published. /.well-known/security.txt returns 404 on every Vendavo host, and neither the security page, the privacy notice nor the contractor security policy names a security@ address. No `VulnerabilityDisclosure` artifact and no `Security` pointer are emitted — there is nothing to point at. docs: - https://www.vendavo.com/security/ - https://www.vendavo.com/contractor-security-policy/ - https://cloudsecurityalliance.org/star/registry/vendavo/ evidence: - {url: 'https://www.vendavo.com/security/', status: 200, keywords: [iso 27001:2022, soc 1 type 2, soc 2 type 2, csa star, caiq, iso 22301, gdpr, cpra]} - {url: 'https://trustvault.vendavo.com/', status: 200, note: 'Scrut.io Trust Center; client-rendered shell, title "Trust Vault"'} - {url: 'https://cloudsecurityalliance.org/star/registry/vendavo/', status: 200, note: 'page title "STAR Registry Entries for Vendavo Inc."'} - {url: 'https://www.vendavo.com/.well-known/security.txt', status: 404}