Acceptable Use Policy
This Acceptable Use Policy ("AUP") governs use of the v3ndor.io platform. It is part of the Terms of Service; capitalized terms have the meanings given there.
1. Prohibited content
You will not upload, store, or transmit through the service:
- Content you do not have the right to use, including third-party confidential material outside of clear authorization scopes (e.g. SOC 2 reports the vendor has marked redistribution-prohibited).
- Malware, exploits, or content designed to damage or interfere with any system.
- Personal data of categories described as "special" under GDPR Art. 9 (race, ethnicity, political opinion, religion, union membership, genetic, biometric, health, sex life, sexual orientation) except where strictly necessary for vendor risk evaluation and where you have a lawful basis.
- Content that infringes intellectual-property rights or trade secrets.
- Content that defames, harasses, threatens, or violates the privacy of any individual.
- Content prohibited by applicable export control or sanctions laws.
2. Prohibited activity
You will not:
- Use the service to send unsolicited commercial communications, spam, or bulk vendor-questionnaire blasts to entities that have not opted in.
- Probe, scan, or test the vulnerability of the service except under our published vulnerability disclosure policy (or a separately signed bug-bounty agreement).
- Attempt to bypass authentication, rate limits, or access controls.
- Reverse-engineer, decompile, or attempt to extract the source code, except where permitted by law.
- Use the service to develop a competing product, including by training a model on the service's outputs to replicate it.
- Resell, sublicense, or otherwise commercially exploit the service except as expressly permitted.
- Impersonate any person or entity.
- Interfere with, disrupt, or impose excessive load on the service or its supporting infrastructure (including denial-of-service or DDoS conduct, regardless of intent).
- Use the service in violation of applicable law, including export controls and sanctions.
3. Vendor outreach & questionnaires
v3ndor.io supports outreach to vendors via the Vendor Portal. When using these features:
- Send only to vendors you have a legitimate business relationship with or are evaluating in good faith.
- Honor each vendor's response timeline and stated communication preferences.
- Do not use vendor portals to phish, scam, or extract data outside the questionnaire scope.
- Comply with applicable anti-spam laws — CAN-SPAM (US), CASL (Canada), ePrivacy Directive (EU/UK).
4. Automated access & APIs
You may use v3ndor.io's published APIs subject to documented rate limits. You may not:
- Scrape the UI to bypass API rate limits.
- Build a wrapper that disguises the source of requests.
- Cache or mirror Customer Data of other tenants by any means.
5. Security & account hygiene
- Maintain reasonable security practices on devices used to access the service: OS patches, screen locks, full-disk encryption, anti-malware.
- Use SSO and MFA for admin accounts. Shared accounts are prohibited.
- Notify security@v3ndor.io within 24 hours of suspected credential compromise.
6. Reporting violations
To report a suspected AUP violation, email abuse@v3ndor.io with the subject AUP report and as much detail as you can share.
6A. Reporting IP infringement
If you believe content on v3ndor.io infringes a copyright or trademark you hold, see the notice-and-takedown procedure in Section 11B of the Terms of Service. Send notices to legal@v3ndor.io with the subject IP infringement notice.
7. Enforcement
We may suspend or terminate access for violations, with immediate effect for violations that pose a security risk or risk of harm to others. We will use reasonable efforts to notify the affected account admin first, except where notification would compound the risk.
← Back to Legal hub