VendorScore Acceptable Use Policy
Last updated: August 31, 2026
This Acceptable Use Policy ("AUP") applies to all use of VendorScore (the "Service") by Customers, their Authorized Users, and any vendor personnel using the vendor portal ("Vendor Users"). It supplements, and is incorporated into, our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
1. Purpose and Scope
VendorScore is built to help organizations manage vendor risk in a Federal Contract Information (FCI) environment. This policy exists to keep the platform safe for every customer on it, and to keep it operating within the boundaries it was built for. It applies equally to client-side users and to vendor-side users of the portal.
2. Prohibited Content
Controlled Unclassified Information (CUI) must never be uploaded, entered, or otherwise submitted to the Service, in any form. VendorScore is designed and operated as an FCI-capable environment. It is not authorized, configured, or intended to receive, store, or process CUI, and Customer is solely responsible for ensuring that nothing submitted to the Service — by Customer, its Authorized Users, or any Vendor User it invites — constitutes CUI.
The following are also prohibited from being uploaded or entered into the Service under any circumstances:
- Classified information of any kind, at any classification level
- Export-controlled technical data subject to ITAR or EAR, beyond what is incidental to describing a vendor relationship in ordinary business terms
- Any other information Customer is under a legal or contractual obligation not to disclose to a third party, where the Service would constitute such disclosure
3. What This Means in Practice
Customer is responsible for training its own Authorized Users, and for instructing any vendor it invites, on what does and does not belong on this platform. This is a policy obligation, not a technical guarantee — the prohibition on CUI applies regardless of what any automated system does or doesn't catch.
If Praetorian Secure, LLC becomes aware, through automated detection, manual review, or any other means, that content submitted to the Service may constitute CUI or other prohibited content, we reserve the right to:
- Restrict access to the affected content pending review
- Decline to process, analyze, or return results for the affected content
- Notify the Customer administrator associated with the affected content
- Request that Customer confirm the nature of the content and, if it is confirmed to be prohibited, remove it
- Suspend the affected account or feature access if the issue is not resolved
- Terminate the agreement for cause, in accordance with the Terms of Service, for repeated or knowing violations
This section describes what we may do, not a technical capability we're representing as active on every upload path today. For a precise, current description of what is and isn't automatically scanned, see our Security Overview.
4. General Prohibited Uses
In addition to the content restrictions above, you may not:
- Attempt to scan, probe, penetration-test, or assess the security of VendorScore's infrastructure without our prior written authorization
- Attempt to access another organization's data, or any account you are not authorized to use
- Reverse engineer, decompile, or attempt to derive the source code of the Service, except to the extent applicable law prohibits this restriction
- Resell, sublicense, rent, or provide access to the Service to any third party not authorized under your subscription
- Scrape, systematically extract, or bulk-export data from the Service other than through features provided for that purpose
- Introduce malware, or attempt to disrupt, degrade, or overload the Service or its infrastructure
- Impersonate another person or organization, or misrepresent your affiliation with a person or organization
- Use the Service to violate any applicable law, including export control and data protection law
- Circumvent or attempt to circumvent any access control, rate limit, or usage restriction in the Service
5. Vendor Portal Use
Vendor portal accounts are provisioned for the purpose of responding to assessments and providing information requested by the inviting Customer. A Vendor User account must only be used by personnel of the vendor it was issued to, authorized to represent that vendor. Sharing a vendor portal account across unrelated organizations, or using it to access or influence another vendor's data, is prohibited.
6. Consequences of Violation
Violation of this policy may result in suspension or termination of access, in accordance with the Terms of Service. Where a violation involves prohibited content under Section 2, we may take the actions described in Section 3 in addition to any remedy available under the Terms of Service.
7. Reporting a Violation
If you believe this policy has been violated — by another user, a vendor, or anyone else with access to the Service — contact us at info@praetoriansecure.com.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to Customer administrators in accordance with the Terms of Service.