⚠️ DRAFT — NOT YET REVIEWED BY COUNSEL
This document sets processor obligations and data-subject-facing commitments. Do not publish or send to a customer until it has been reviewed by a lawyer. Everything below is a working draft.
VendorScore Privacy Policy
Effective date: August 31, 2026
1. Scope and Our Role
This Privacy Policy describes how Praetorian Secure, LLC ("VendorScore," "we," "us") handles information in connection with the VendorScore platform (the "Service").
We act in two different roles, depending on the data:
- For Account Data (information about our direct customers and their Authorized Users, such as login credentials and admin contact details), we act as a controller.
- For Vendor Data (information our customers or their vendors submit about vendor relationships, including vendor contact information), we act as a processor, acting on our customer's instructions under our Terms of Service. If you are a vendor contact whose information appears in VendorScore because a company you work with uses the Service, that company is the controller of your information, not us — please direct requests about your information to them in the first instance.
2. Information We Collect
Account Data, from our direct customers and their Authorized Users:
- Name, email address, and role
- Login credentials and multi-factor authentication enrollment status (we do not store your authenticator app's secret in a form usable by us to generate codes ourselves; MFA is enforced, not something we can bypass on your behalf)
- Actions taken within the Service, recorded in our audit log (see Section 5)
Vendor Data, submitted by our customers or by vendor contacts through the vendor portal:
- Vendor company and contact information, including vendor contact email addresses — processed on our customer's behalf, as their instructed processor, to deliver assessment invitations and related communications
- Assessment responses and supporting documentation
- Contracts, credentials, evidence documents, and related files a customer or its vendor uploads
Technical Data, collected automatically:
- IP address and browser user agent, recorded for security-relevant actions in our audit log
We do not use any third-party analytics or advertising tracking on the Service. The only cookie the Service sets is a first-party session cookie required to keep you logged in — it is not used for tracking or advertising.
3. How We Use Information
We use the information above to:
- Operate, maintain, and secure the Service
- Send transactional email on our customer's behalf — assessment invitations, reminders, and account notifications — via our email delivery sub-processor
- Provide AI-assisted analysis features (such as contract clause analysis, narrative generation, and evidence review) — where a customer uses these features, the relevant uploaded document content is sent to our AI sub-processor to generate that analysis
- Look up publicly available federal vendor registration information from SAM.gov, where a customer's vendor monitoring configuration requests it — this involves querying a public government data source about a vendor's public registration status; it does not involve sending Vendor Data to SAM.gov
- Maintain a security audit trail of actions taken in the Service
4. Sub-processors
We use the following sub-processors to provide the Service:
| Sub-processor | Purpose | What it processes |
|---|---|---|
| Railway | Application hosting and database infrastructure | All Account Data and Vendor Data, as the underlying infrastructure the Service runs on |
| Cloudflare R2 | Document storage | Uploaded files (contracts, credentials, evidence, and related documents) |
| Resend | Transactional email delivery | Recipient email addresses and the content of transactional emails (assessment invitations, reminders, notifications) |
| Anthropic | AI-assisted document analysis | Content of documents a customer submits to an AI-assisted analysis feature (e.g., contract text, evidence documents), for the purpose of generating that analysis |
We do not treat SAM.gov as a sub-processor: it is a public data source we query for publicly available federal registration information, not a party we send Vendor Data or Account Data to.
We will update this list if we add or change a sub-processor that processes Account Data or Vendor Data.
5. Audit Logging
Security-relevant actions taken in the Service — including logins, role changes, document uploads and deletions, and administrative actions — are recorded in an append-only audit log, along with the acting user, the action taken, a timestamp, and (where applicable) the IP address and browser used. This log cannot be altered or deleted, including by us. See our Security Overview for more detail on how this is enforced.
6. Where Data Is Stored
The Service is hosted in Railway's us-west2 region. Data is not currently replicated to or processed in any other region.
7. Data Retention
We retain Account Data and Vendor Data for as long as the applicable customer account is active, and thereafter as described in our Terms of Service. Individual records can typically be deleted directly within the Service by an authorized user; full account closure is handled as described in our Terms of Service.
8. Security
We maintain administrative, technical, and physical safeguards for the information we process, described in detail in our Security Overview.
9. Your Rights and Requests
Depending on your relationship to the Service and applicable law, you may have rights to access, correct, export, or request deletion of information we hold about you.
- If you are an Authorized User of a customer account, contact your organization's administrator, or contact us directly at info@praetoriansecure.com.
- If you are a vendor contact whose information was submitted by one of our customers, please contact that customer directly, as they control that information; we will support their request to us as their processor.
Submit requests to info@praetoriansecure.com. Requests received directly from individuals will be routed to the relevant Customer administrator for identity verification and handling. We will respond within thirty (30) days of a verified request.
10. Children's Privacy
The Service is a business tool not directed to, or intended for use by, individuals under 18. We do not knowingly collect information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here and update the effective date above; for material changes, we will provide additional notice to customer administrators.
12. Contact Us
Questions about this Privacy Policy can be sent to:
Praetorian Secure, LLC 3072 N Irish Rd, Davison, MI 48423 info@praetoriansecure.com