Trust & data

Clear about the evidence.
Clear about the limits.

Vendarity is being developed as a supplier-evidence operations workspace. It does not certify legal compliance, validate insurance coverage or guarantee an audit outcome.

Human decisions remain central

People assess evidence against customer-configured requirements. Every metadata field needs a human review decision before acceptance. AI field extraction is not available yet. The manual review workflow works without it.

Data locations

The proposed production architecture uses a Hostinger application server in Singapore and private Backblaze B2 storage in US East, with a separately protected backup account. Actual regions and subprocessors must be confirmed before live use. This is not Australian-only hosting.

Access and records

The development implementation uses workspace membership checks, PostgreSQL row-level security and separate runtime credentials. Privileged access to real workspaces requires authenticator-based MFA. Decision records and document metadata are append-only to the application runtime.

Retention and recovery

The specified policy defaults to five years after supersession or supplier archive, with selectable 1/3/5/7-year periods. Active supporting evidence is retained. Planned account closure includes 30 days of read-only export access and up to 35 additional days in recovery backups. Implementation and recovery drills remain part of release acceptance.

Current readiness

The app is in development. Independent security review, production storage verification, live provider checks, full recovery drills and qualified legal/privacy/tax review have not been completed. No SOC 2, ISO 27001 or other certification is claimed.

Appropriate evidence

Vendarity is intended for business supplier documents across industries, including quality certificates, policies and insurance evidence. Do not submit medical records, government identity documents, payment-card details or employee credentialing records.