SOC2C

Is this your company? Buyers are checking VendorPanel here. Claim vendorpanel.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
VendorPanel logo

VendorPanel

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

VendorPanel is SOC 2 Type II compliant. VendorPanel also holds PCI DSS, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

VendorPanel operates a market-leading Source-to-Pay platform for the management of strategic and operational procurement in North America and Asia Pacific. By integrating access to a range of sourcing options and driving best practice in managing decentralised spend, it helps clients optimise value, manage risk, and support their business objectives in areas including local supplier engagement and social procurement.

Compliance & infrastructure

Documents

4

Subprocessors

3
  • S
    Slack · Collaboration
  • O
    Office 365 · Document management
  • V
    Vanta · Security

Compliance leadership

The person who leads VendorPanel's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. VendorPanel's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is VendorPanel SOC 2 compliant?
VendorPanel is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is VendorPanel PCI DSS compliant?
According to VendorPanel's public trust center, VendorPanel is PCI DSS compliant. On SOC2C this listing is Listed.
Is VendorPanel HIPAA compliant?
According to VendorPanel's public trust center, VendorPanel is HIPAA compliant. On SOC2C this listing is Listed.
Is VendorPanel SOC 2 Type I or Type II?
VendorPanel is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use VendorPanel's SOC 2 for a vendor risk assessment?
Yes. VendorPanel's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by VendorPanel

Reproduced from VendorPanel's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Want to report a potential security issue?
Please immediately reach out to our Support team. You can reach them via: - in system live chat (Quickest response) - submit a request at https://vendorpanel.zendesk.com/hc/en-us/requests/new - Email us at support@vendorpanel.com.au
Where can I find information about VendorPanel's uptime and downtimes?
We recommend checking out our status pages. This will give you the ability to see any current status updates, subscribe for updates, view uptimes, be informed of any outages, and view historical data. See below for status page links for each region: - Australia - https://au-uptime.vendorpanel.com/ - United States - https://net-uptime.vendorpanel.com/ - New Zealand - https://nz-uptime.vendorpanel.com/ - Canada - https://ca-uptime.vendorpanel.com/
Describe detection methods you have in place for identifying security and privacy incidents as quickly as possible
We have internal application systems that raise alerts when anomalies are detected along with external application and platform monitoring systems that raise alerts when anomalies are detected.
Do you encrypt data at rest?
Yes, all data is encrypted in flight and at rest and all backup data is encrypted prior to its move to off-site facilities. You can find additional information in our Cryptography Policy
Do you support Single Sign-On (SSO)?
Yes, we prefer customers leverage our SSO functionality. We support: - OpenID 2.0 - OpenID Connect / OAuth2 Login - SAML 2.0

Business & Industrial peers that completed SOC 2