Trust center
Security is part of the operating model.
VendPatch uses layered controls appropriate for a supervised pilot and publishes current limitations instead of overstating certification.
Tenant isolation
PostgreSQL row-level security scopes company records. Role and assignment tests run against the database.
Private files
Files use private object storage and five-minute signed downloads. Upload types, signatures, references, and size are validated.
Public abuse controls
Public forms use origin checks, bounded request bodies, honeypots, hashed network identifiers, serialized rate limits, and limited metadata.
Application protection
Security headers block framing, MIME sniffing, risky browser capabilities, insecure transport, and unapproved content sources.
Operational checks
CI runs lint, type checks, builds, dependency audits, smoke tests, and database isolation tests. Production health checks cover the database and file storage.
Current scope
VendPatch has not claimed SOC 2, ISO 27001, PCI DSS certification, or formal penetration-test coverage. Do not submit payment-card numbers.
Report a concern
Pilot customers should contact their named VendPatch pilot coordinator immediately. Include the affected page and time, but never send passwords, access tokens, card numbers, or copied customer records. Critical reports are acknowledged under the pilot support commitment.