Security and privacy
You trust Vendasta with sensitive business data and rely on Vendasta to be a responsible custodian of your clients' data as well. Vendasta protects that data with independently audited controls, and its security posture is maintained to meet the standards expected across the industries you serve.
This page explains Vendasta's approach at a high level and points you to where the underlying documentation lives. The Vendasta Trust Center is the source of record for everything below.
For security documentation, privacy policies, and reporting, visit the Vendasta Trust Center. Send any security question from you or your clients there first, or email security@vendasta.com.
SOC 2® reporting
Vendasta and Yesware maintain a current System and Organization Controls (SOC 2®) Type 2 report, issued by an independent auditor.
A SOC 2 Type 2 report examines the design and operating effectiveness of an organization's controls over a defined period, measured against the Security Trust Services Criterion. It gives your own auditors and security teams the detail they need for vendor risk management.
The report itself is confidential and its use is restricted. Vendasta shares it with you and others who need it for due diligence, typically under a non-disclosure agreement. Because the report is gated, this page does not reproduce its contents.
SOC 3® report
Vendasta also publishes a SOC 3® report on the Trust Center, publicly and with no NDA required. Its content is largely identical to the SOC 2® Type 2 report, with the confidential, NDA-sensitive detail removed.
A SOC 3 report can only be issued alongside an unqualified SOC 2 Type 2 opinion, so its availability is itself evidence that Vendasta and Yesware passed the audit without exceptions.
For most vendor reviews, the SOC 3 report gives your prospects and clients everything they need: independent confirmation that Vendasta and Yesware are SOC 2 Type 2 attested, without the wait or paperwork of an NDA. Point them to the SOC 3 first. Reserve the full SOC 2 Type 2 report for cases where a client's own vendor risk process specifically requires the detailed control testing it contains.
Request security documentation
When you or your client's security team needs to complete a vendor review, find these through the Vendasta Trust Center:
- SOC 3 report – Publicly available, no request or NDA required
- SOC 2 report – Available on request; access to gated documents may require a non-disclosure agreement
- Security control summary – The current, published summary of Vendasta's controls
- Subprocessors – The current list of third-party subprocessors Vendasta uses
For anything the Trust Center does not answer, contact security@vendasta.com.
Privacy and data protection
Vendasta's privacy practices govern how data is collected, processed, and protected across the platform. The following are available through the Trust Center:
- Customer Privacy Policy – How Vendasta handles personal data
- Cookie Policy – How cookies and similar technologies are used
- California Privacy Rights – Disclosures for California residents
- GDPR – The data subject policy and procedure, and the personal data breach incident response procedure
Related settings
Several Partner Center settings connect to how access and data are secured in your own account:
- Single Sign-On – Let clients access products with your organization's logins
- Service accounts – Manage automated access and API keys for integrations
- Data management – Organize and control your business data