Minimum requirements
- Encryption in transit and at rest for our data
- Multi-factor authentication and least-privilege access for vendor staff
- Documented incident response with notification to us without undue delay
- Secure development practices and timely patching of known vulnerabilities
- Background-appropriate personnel screening and confidentiality obligations
Assessment
Vendors handling personal or confidential data complete a security questionnaire and provide available attestations, such as SOC 2 or ISO 27001 reports, before onboarding.
Ongoing review
High-risk vendors are reviewed at least annually and whenever the scope of data access changes materially.
Offboarding
On termination, vendors delete or return our data and certify completion.
Changes to this document
We may update this document as our services, technology, and legal obligations evolve. Material changes are published with a new version number, an updated effective date, and a summary of changes in the version history below.
Continued use of our websites, products, services, experiences, or communities after an update takes effect constitutes acceptance of the current version.
Contact
Questions about this Vendor Security Standards may be sent to our legal and compliance contact through the contact form on this site. Please reference the document title and version number.
- Legal & compliance requests: use the Contact Legal link on this page
- Privacy and data rights requests: see the Consumer Privacy Rights policy
- Accessibility accommodations: see the Accessibility Statement
Review notice
This document is a high-quality draft template prepared for review. It is not legal advice and no guarantee of compliance is made or implied. Final responsibility for legal sufficiency rests with the organization's licensed legal counsel.
Onboarding as a vendor?
Complete our security review to move quickly through procurement.