Practical, evidence-rich controls

Security is a release gate

Vendor content is hostile input, tenant access is checked server-side, billing state is verified, and autonomous remediation has narrow deterministic authority.

Architecture

Secure, same-site HTTP-only sessions; parameterized typed queries; explicit tenant filters; encrypted integration secrets; signed inbound and outbound webhooks; strict validation; CSP and secure response headers; rate limits; immutable audit events; and least-privilege provider adapters.

Source safety

Connectors require HTTPS allowlists, DNS resolution checks, private-address blocking, redirect revalidation, size/time limits, safe media types, sanitized snapshots, and deterministic extraction. Instructions inside fetched content never alter behavior.

Responsible disclosure

Send a concise report to security@example.invalid. Do not access another customer’s data, disrupt service, exfiltrate secrets, or use social engineering. We acknowledge credible reports through the accountable-owner incident path.

Claims

VendorEpoch does not claim SOC 2, ISO 27001, HIPAA, PCI, or other certification unless independently obtained and explicitly listed here. Payment-card data remains with the merchant of record.