Platform
Enterprise architecture from day one
VendorQ is built as multi-tenant SaaS with tenant isolation, role-based access control and auditability at the core.
True multi-tenancy
Every record belongs to an organization and is isolated at the database level with row-level security — not just hidden in the UI.
Granular RBAC
Org admin, vendor risk manager, security analyst, compliance analyst, procurement, business owner, executive, auditor and standard user roles, plus separate vendor-portal roles.
Audit logging
Logins, invitations, role changes, vendor and assessment activity, evidence access, score changes, approvals and settings changes are recorded.
Secure evidence storage
Tenant-scoped storage paths and signed URLs. Buckets are never public.
Explainable scoring
Configurable weighting across questionnaire, certifications, external posture, vulnerabilities, incidents, criticality and data sensitivity.
White label
Partners and enterprise customers can present the platform under their own brand, logo, sender identity and domain.