Vendorisk.ai // Legal & policy

Unreviewed draft // pending legal review

This document was drafted from the application's actual data flows and has not been reviewed by counsel. It is not yet legally binding and must be reviewed, completed (see the bracketed placeholders throughout, indexed under Placeholders to complete) and approved before Vendorisk.ai is offered to customers.

Document 04 // Contact

Contact Analyst

There is no contact form here on purpose: a form that quietly goes nowhere is worse than an address. Pick the route below that matches what you need - the fourth one, disputing an assessment, is the one we most want vendors to use.

Last drafted: 2026-07-31 · Version: draft 0.1 · Effective date: [Policy effective date]

01

General and sales

[General contact email]

Product, pricing, plans, press

02

Privacy and data rights

[Privacy contact email]

Access, correction, erasure, export

03

Security disclosure

[Security contact email]

Vulnerability reports only

04

Dispute an assessment

[Disputes contact email]

Vendors and named individuals

Postal correspondence: [Legal entity name], [Registered address]. Addresses are shown as placeholders until the operator publishes them; do not treat them as live.

01. General and sales

For questions about what Vendorisk.ai does, whether it fits your procurement process, plans and seats, invoicing arrangements, or a press enquiry, write to [General contact email]. Billing changes you can make yourself - upgrading, downgrading, updating a card, cancelling - are faster through the billing page, which opens the Stripe customer portal.

Please do not send security findings or data subject requests to this address; they will be slower to reach the right person.

02. Privacy and data subject requests

Requests to access, correct, delete, restrict, port or object to the processing of your personal data go to [Privacy contact email]. The same address reaches us for questions about our privacy policy and for a copy of the safeguards we rely on for international transfers.

What to include

  • The email address on the account, so that we can find it.
  • Which right you are exercising, and what you would like to happen.
  • If your request concerns a specific workspace, its name - an account may belong to more than one.

Two honest notes. There is no self-service export or delete button in the product yet, so these requests are handled by a person rather than instantly. And where your employer administers the workspace, some content is theirs to decide about, so we may need to involve them.

03. Security disclosure

Vulnerability reports go to [Security contact email]. Read the security disclosure policy first: it sets out what is in scope, what is not, our safe-harbour commitment for good-faith research, and what to include in a report.

One thing that is not a Vendorisk.ai security issue: a vulnerability in a company that one of our dossiers describes. Those are unrelated third parties, and the report belongs with them, under their own disclosure policy.

04. Dispute an assessment

If you work for a company we have assessed, or you are named in a dossier, and you think we have it wrong, this is the route that matters. We would rather be corrected than be confidently inaccurate, and we treat a well-evidenced dispute as a bug report against our research. Write to [Disputes contact email].

What to include

  1. The company - its name and primary domain, so that we match the right record and not a similarly named one.
  2. The dossier URL - the page you are looking at.
  3. The specific claim - quote the sentence, event, risk tier, score or citation you dispute. A request to review the whole dossier is much slower to act on than a pointer to one line.
  4. The public evidence that contradicts it - a published statement, a regulatory filing, a status-page history, a current certification or audit report, a corrected or retracted news article. Public sources are what we can cite in a correction.
  5. Your role - whether you are authorised to speak for the company, or are an individual named in the leadership notes.

How we handle it

Where a claim is not supported by the source we cited, or the source has since been corrected or withdrawn, we amend or remove the claim and re-run the assessment. Where a claim accurately reports what a public source said, we will normally keep it and annotate it with your response and any newer evidence, rather than deleting accurate reporting. If you are an individual named in a dossier and you object to the processing, say so explicitly and we will treat it as an objection under the privacy policy.

We do not accept payment, advertising, a commercial relationship or a threat as a reason to change a risk tier. Assessments are not for sale in either direction, and telling us so will not speed anything up.

05. What to expect

We are a small team, so here is what is realistic. General enquiries: [Support response SLA]. Privacy and data subject requests: [DSAR response SLA], and in any event within the statutory period. Security reports: see the acknowledgement and triage targets in the security disclosure policy. Disputes: we will confirm receipt, tell you what we are checking, and come back with the outcome and any change we made.

What we cannot do: give legal, regulatory or security advice; certify or attest to any vendor's compliance; act as an intermediary between you and a vendor; or confirm what any other customer has researched. The nature and limits of the assessments themselves are set out in the terms of service.

99. Placeholders to complete

Every bracketed placeholder used on this page is listed below. Each one is a fact the application's source code cannot supply and the operator must fill in before this document is published as binding.

  • [Policy effective date]
  • [Legal entity name]
  • [Registered address]
  • [General contact email]
  • [Privacy contact email]
  • [Security contact email]
  • [Disputes contact email]
  • [Support response SLA]
  • [DSAR response SLA]