Home / Features / Security and data handling
Feature

Vendor Data Security
You are holding other companies’ information

Supplier onboarding collects tax identifiers, banking details, insurance documents and signed attestations, and none of it belongs to you. That is worth taking seriously, and it is worth being able to explain rather than gesturing at a badge.

Access scoped by roleRecords you can export
What actually protects supplier data

Fewer moving parts, and a record you cannot quietly edit

Security conversations tend to jump straight to certifications. The practical questions are simpler: who can reach it, what happened to it, and can you get it back.

Outcome

Fewer people can reach it than you think

Access is scoped by role rather than granted per person, so the number of people who can see banking details is a decision rather than an accumulation.

In practiceAn access review you can complete and explain.
Outcome

Nothing changes without a trace

Entries are recorded as work happens and corrections are added rather than overwriting what was there, so the sequence of events holds its shape.

In practiceYou can say what you held and when, months afterwards.
Outcome

The data stays yours

The directory, the documents and the scores export in full. Supplier information is used to qualify suppliers for you and nothing else.

In practiceNo dependency you cannot walk away from.
The questions worth asking a vendor

Ours included

These are the four we would ask, and we would rather answer them plainly than point at a logo.

Book a demo
The challenge

Whoever has a login

Access is broad by default and narrowed later if somebody raises it, which means the answer to who can see banking details is usually more people than intended.

DefaultBroad
NarrowedOn request
AnswerUncomfortable
With VendorHub

Whoever the role allows

Roles carry their scope and people sit in roles, so the population who can reach sensitive fields is deliberate and reviewable.

DefaultScoped
NarrowedBy design
AnswerSpecific
The challenge

A current state

The system shows what a record says now, and what it said last month is not recoverable, so mistakes and changes look identical.

HistoryOverwritten
SequenceUnknown
ExplainingHard
With VendorHub

A recorded sequence

Actions are recorded as they happen and corrections are added as further entries, so what changed and when is visible.

HistoryPreserved
SequenceVisible
ExplainingStraightforward
The challenge

Another account

Every supplier account is another credential to be reused, shared or lost, and a portal full of them is a larger surface than it looks.

AccountsMany
CredentialsMore
SurfaceLarger
With VendorHub

Nothing at all

Suppliers work from a secure link with no account and no password, which removes a whole category of credential problem.

AccountsNone
CredentialsNone
SurfaceSmaller
The challenge

A support request

Export is limited or partial, which is a commercial position rather than a technical one, and it is worth discovering before you commit.

ExportRestricted
CompletenessPartial
ExitDifficult
With VendorHub

A file, whenever you like

The directory exports in full with scores, categories and document links, and we would encourage you to test it during evaluation.

ExportFull
CompletenessWhole record
ExitPossible
Questions we get asked

About security and data handling

Is vendor data safe in VendorHub?
Supplier data is scoped by role so only the people you intend can reach it, every action is attributed and recorded, records cannot be quietly rewritten, and you can export everything at any time. Those are the properties that matter day to day.
Who can see the data we collect?
Whoever the roles you configure allow. Access comes from the role rather than being granted per person, which keeps the population deliberate and reviewable.
Can records be changed after the fact?
Corrections are added as further entries rather than overwriting what was there, so the sequence of what happened is preserved rather than replaced.
Do suppliers need accounts?
No, and that is a security decision as much as a usability one. Suppliers work from a secure link with no password to manage, lose or reuse.
Is supplier data used for anything else?
No. Information collected during onboarding is used to qualify suppliers for you. It is not sold on or used for any other purpose.
Can we get our data out?
Yes, in full, including scores, categories and document links. We would encourage you to test the export during an evaluation rather than taking it on trust.
What certifications do you hold?
Ask us directly and we will tell you exactly where we stand rather than implying more than is true. We would rather have that conversation properly than list badges on a webpage.
What happens to data if we leave?
You export it, and we will talk you through retention and deletion on the call so the answer is specific to your arrangement rather than generic.
Related

Other parts of the workspace

FEATURE

Team and roles

How access is scoped, and how it moves when people do.

Read more
FEATURE

Approvals and activity

What is recorded, and what needs a person.

Read more
FEATURE

Import and export

Getting your data out, in full.

Read more

Bring your security questionnaire

We would rather work through it properly on a call than have you infer our position from a webpage.