Vendor Security Addendum review
Linter for a Vendor Security Addendum / Information Security Exhibit. Checks cover specific measures enumerated, security-review cadence, right-to-audit or SOC 2 substitution, incident-response notification window, vulnerability-disclosure handling, secure-development-lifecycle reference, data-classification mapping, named encryption standards, penetration-test cadence.
Review your document — free → See a sample report- 9 document-specific checks
- + 115 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
Specific security measures listed
Vendor Security Addendum must enumerate specific security measures rather than a generic 'industry-standard' hand-wave.
Warning · ADDENDA-001
Security-review cadence stated
Vendor Security Addendum must state the cadence for security reviews / audits / certifications.
Warning · ADDENDA-002
Right-to-audit or SOC 2 substitution
Vendor Security Addendum must provide a right-to-audit (customer-initiated) or a SOC 2 / ISO 27001 substitution clause.
Warning · ADDENDA-003
Incident-response notification window
Vendor Security Addendum must specify a notification window for security incidents.
Warning · ADDENDA-004
Vulnerability-disclosure handling
Vendor Security Addendum should state how it handles externally-reported vulnerabilities.
Note · ADDENDA-005
Secure-development-lifecycle reference
Vendor Security Addendum should reference a secure-development-lifecycle (SDLC) program.
Note · ADDENDA-006
Data-classification mapping
Vendor Security Addendum should state how Customer Data is classified and the controls that follow.
Note · ADDENDA-007
Encryption standards named (FIPS 140-3 / AES-256)
Vendor Security Addendum should name encryption standards (FIPS 140-3 / AES-256 / TLS 1.2+).
Warning · ADDENDA-008
Penetration-test cadence stated
Vendor Security Addendum should state pen-test cadence.
Note · ADDENDA-009
Every run also applies 115 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Sources
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
More privacy & data protection documents
- Biometric Data Consent (BIPA-style)
- Children's Privacy Notice (COPPA)
- Cookie / Tracking Notice
- Data Sharing Agreement (Research / Inter-Agency)
- DPA — CCPA Service Provider (CPRA-aligned)
- DPA — Controller to Processor (EU/UK)
- DPA — Multi-State US (CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, DPDPA)
- DPA — Processor to Sub-Processor (EU/UK GDPR)
- Data Protection Impact Assessment (GDPR Art. 35)
- Data-Incident Notification Template
- Privacy Notice (GDPR)
- Privacy Notice (US / CCPA)
- Privacy Policy Linter
- Records of Processing Activities (GDPR Art. 30)
- EU Standard Contractual Clauses — Module 2 (Controller to Processor)
- EU Standard Contractual Clauses — Module 3 (Processor to Processor)
- SMS / Telemarketing Consent Disclosure
- UK International Data Transfer Addendum / IDTA
- Vendor Security Questionnaire (SIG / CAIQ)