Skip to content

Security

Held to the standard we help you check.

You trust SaaSint Vendor Risk with evidence about your vendors' security. Here is exactly how we protect it, and exactly where we are on formal certification. It's the same discipline we bring to the systems we build for clients.

How we protect your data

01

Tenant isolation in the database

Every customer's records carry their organization, and Postgres row-level security returns only your organization's rows. Isolation doesn't depend on our application code remembering to filter, and automated tests try to read across organizations on every change.

02

An audit log that can't be quietly edited

Every change, evidence download, vendor submission and report export is recorded with who did it and when. The database rejects edits and deletions of log entries from every role the application uses.

03

Vendor links built as credentials

Questionnaire links carry a random 256-bit token. We store only its hash, so a copy of our database can't be used to open them. Each link reaches exactly one questionnaire, expires after 30 days, and can be revoked or replaced.

04

Private evidence storage

Documents live in private storage. Each download is checked against your organization's access first, then served through a link valid for 60 seconds, as a download, never rendered in our site.

05

Verified identities

Sign-in goes through Zitadel. We only use an email address once your identity provider has verified it: for expiry reminders, for your billing account, and to label your actions in the audit log.

06

No card data

Payments are handled by Dodo Payments as merchant of record. Card details never reach our servers.

Compliance status

Plainly, no spin.

SOC 2
We are not SOC 2 certified. We build to SOC 2-aligned practices today, and plan a Type I audit once we have paying customers and stable core workflows, followed by Type II. We won't claim certification before a report exists.
Data residency
Pinning an organization's data to an EU or South African region is planned, not available yet. Ask us where your data would be hosted before you sign up.
Single sign-on
SAML/OIDC single sign-on and SCIM provisioning are planned for enterprise customers, not available yet.

Infrastructure providers

These services process data on our behalf.

SupabaseDatabase and document storage
VercelApplication hosting
ZitadelSign-in and identity
ResendReminder and contact emails
InngestScheduled jobs (reminders, cleanup)
Dodo PaymentsSubscription payments

Questions or a security review?

We're happy to walk your security team through any of this.