Security

Your data. Protected.

Procurement data is some of the most sensitive data a company holds. Supplier terms, pricing, ownership records, screening results. We run information security as an audited management system, and an accredited body checks that we actually do it.

Talk to our security team
Quality Asia certification mark

ISO-27001

QA-00224

NABCB accreditation symbol IS-013

How we protect your data

Encrypted in transit and at rest

Traffic to and inside our platforms runs over TLS, database connections included. Stored data is encrypted at rest on managed cloud infrastructure.

Client data stays separate

A dedicated application and database, or enforced row-level isolation. No client can reach another client’s data.

Your identity provider

Single sign-on through your own identity provider, under your MFA policy, with roles taken from your security groups.

Your hosting region

For dedicated deployments you choose where the data lives, so residency requirements are met before anything is loaded.

Least privilege by default

Role-based access limits every person to the categories and suppliers in their remit. Nobody sees the whole estate because they happened to log in.

No AI training on your data

Our products use commercial AI APIs whose terms exclude client data from model training. What you submit stays yours.

Running a security review?

We will send the certificate, complete your security questionnaire, and walk your team through the architecture of the product you are evaluating.

Found a security issue in one of our products? security@vantixe.com reaches the people who can fix it.

Vantixe Advisory Limited operates an ISO/IEC 27001:2022 certified information security management system. The certified scope covers the development, operation and delivery of our procurement software products and consulting services. Certification applies to the management system, not to individual products.