VendorVault
Home Contact

Trust & Security

Trust and Security

A plain-English overview of VendorVault security, data protection, access controls, integrations, and responsible platform operation.

Last updated: August 2026

1. Our Approach to Security

VendorVault is operated by Portfolioapp Pty Ltd. We understand that real estate professionals may use VendorVault to manage property information, documents, client details, buyer information, workflow dates and other information that requires appropriate protection. Security and privacy are therefore important parts of how VendorVault is designed and operated. This page provides a plain-English overview of our approach to security, data protection and responsible platform operation. It should be read together with our Privacy Policy and Terms of Service.

VendorVault takes a risk-based approach to protecting the information handled through the platform. We aim to use reasonable technical and organisational safeguards appropriate to the nature of the information we process and the size and operation of our platform. Our security approach includes measures relating to:

  • authenticated access;
  • access permissions;
  • encrypted connections;
  • secure infrastructure;
  • data storage;
  • third-party providers;
  • monitoring;
  • backups;
  • software maintenance;
  • account security;
  • incident response; and
  • responsible data handling.

No online platform can guarantee absolute security, but we continually review and improve the controls used to protect VendorVault and its users.

2. Secure Connections

VendorVault uses encrypted HTTPS connections to protect information transmitted between supported web browsers, devices and the VendorVault platform. Encryption in transit helps reduce the risk of information being intercepted while being transmitted across the internet. Users should ensure they access VendorVault through supported, up-to-date browsers and secure devices.

3. Authentication

Access to private VendorVault functionality requires authenticated user access. Authentication controls are designed to help ensure that users can only access functionality associated with their authorised account. Users are responsible for:

  • maintaining the confidentiality of their login credentials;
  • using secure passwords;
  • protecting devices used to access VendorVault;
  • not sharing login details with unauthorised people; and
  • notifying VendorVault if unauthorised account access is suspected.

We may introduce or enhance authentication protections as VendorVault evolves.

4. Access Controls and Permissions

VendorVault is designed around controlled access to property workflows and information. Depending on the functionality being used, access may be restricted according to:

  • the user's account;
  • organisation or agency membership;
  • property Vault;
  • user role;
  • invitation status; and
  • permissions associated with particular functionality.

Users should only be given access to information that is reasonably necessary for their role. VendorVault may use role-based or permission-based controls to help restrict access to particular information. For example, certain buyer, identity or compliance information may require more restricted access than general property workflow information.

5. Property Vault Security

VendorVault may allow users to create property workspaces known as “Vaults”. A Vault may contain information such as:

  • property details;
  • vendor information;
  • uploaded documents;
  • tasks;
  • notes;
  • campaign information;
  • calendar dates;
  • contractor information;
  • buyer information;
  • compliance information; and
  • other property-related records.

Access to Vault information is designed to be limited to authorised users and invited participants according to the functionality and permissions available. Users remain responsible for ensuring that invitations and access permissions are provided only to appropriate people.

6. Data Protection

VendorVault takes reasonable steps designed to protect information against:

  • unauthorised access;
  • unauthorised disclosure;
  • misuse;
  • interference;
  • alteration;
  • loss; and
  • inappropriate access.

Security measures may include a combination of technical, operational and administrative controls. The appropriate controls may vary depending on the type and sensitivity of information being handled.

7. Cloud Infrastructure

VendorVault uses third-party cloud and infrastructure providers to operate the platform. These providers may support services including:

  • application hosting;
  • databases;
  • file storage;
  • networking;
  • authentication;
  • backups;
  • email delivery;
  • monitoring; and
  • other infrastructure required to operate VendorVault.

We seek to use reputable technology providers and services appropriate for a modern cloud-based software platform. Third-party providers operate their own systems and security environments, and VendorVault does not control every aspect of their infrastructure.

8. Data Storage

Information processed through VendorVault may be stored using secure cloud infrastructure and associated storage systems. Depending on the type of information, data may be stored within:

  • application databases;
  • secure file storage;
  • system logs;
  • backups; and
  • other systems reasonably required to provide and protect the Service.

We aim to restrict access to systems containing user information to authorised systems, personnel and service providers where reasonably necessary.

9. Backups and Resilience

VendorVault may use backup, redundancy and recovery processes designed to help maintain service availability and reduce the risk of permanent data loss. Backup and recovery arrangements may vary across infrastructure providers and services. While reasonable measures may be used to maintain data resilience, no cloud service can guarantee that information will never be lost or unavailable. Users should retain independent copies of particularly important documents or records where required for legal, regulatory or business purposes.

10. Third-Party Service Providers

VendorVault relies on third-party technology providers to deliver certain parts of the Service. These may include providers of:

  • hosting and infrastructure;
  • database services;
  • authentication;
  • payment processing;
  • email services;
  • SMS or communication services;
  • analytics;
  • monitoring;
  • calendar integrations;
  • identity verification;
  • document services; and
  • other software infrastructure.

Where personal information is provided to a service provider, we aim to limit that information to what is reasonably necessary for the provider to perform its function. Further information about how personal information may be disclosed or processed is available in our Privacy Policy.

11. Integrations

VendorVault may integrate with third-party platforms such as:

  • Google services;
  • Microsoft services;
  • calendars;
  • CRMs;
  • email providers;
  • property platforms;
  • payment services;
  • document systems; and
  • other productivity tools.

Where available, integrations are intended to use recognised authentication and authorisation methods rather than requiring users to provide their third-party passwords directly to VendorVault. We aim to request only the permissions reasonably required to provide the selected integration. Users may be able to revoke integration access through VendorVault or through the relevant third-party provider.

12. Google and Microsoft Connections

Where users connect supported Google or Microsoft services, VendorVault may receive permission to interact with selected services on the user's behalf. For example, calendar integration may require permission to create, update or synchronise property-related events. Access granted through these integrations is intended to be used only for the functionality requested by the user and related security and operational purposes. Users can generally review or revoke connected application access through their Google or Microsoft account settings.

13. Payment Security

VendorVault may use specialist third-party payment processors to manage subscription payments. Where payments are processed directly by a payment provider, VendorVault does not ordinarily store complete credit or debit card details. Payment providers maintain their own security controls and compliance arrangements. VendorVault may receive limited payment information such as:

  • subscription status;
  • transaction identifiers;
  • payment status;
  • billing information; and
  • limited payment method details.

14. Identity and Compliance Information

Some VendorVault functionality may involve identity verification, regulatory compliance or transaction compliance information. Because this type of information may require additional protection, access may be restricted according to user role and functionality. Where specialist third-party providers perform identity verification or similar services, information may be provided directly to or processed by those providers. VendorVault aims to collect or process only information reasonably required to provide the relevant functionality.

15. Buyer Information

Buyer information may be subject to different access permissions from general seller-facing property information. Where VendorVault provides buyer-related or compliance functionality, the platform may use access controls intended to limit buyer information to authorised users. Users remain responsible for ensuring that buyer information is collected, accessed, used and disclosed appropriately.

16. Seller and Client Access

VendorVault may allow agents or other authorised users to provide sellers or clients with access to selected information about their property workflow. Seller or client access is intended to provide transparency without automatically providing access to every piece of information held within an agent's or agency's VendorVault account. The information available to a seller or client depends on the relevant functionality and permissions. Users are responsible for ensuring that the correct people are invited and that their access remains appropriate.

17. Logging and Monitoring

VendorVault may maintain technical logs and monitoring information relating to the operation and security of the platform. This may include information concerning:

  • application activity;
  • authentication events;
  • system errors;
  • performance;
  • infrastructure;
  • security events; and
  • other technical activity.

Logging and monitoring may be used to:

  • maintain platform reliability;
  • identify technical problems;
  • investigate suspected misuse;
  • detect security issues;
  • improve performance; and
  • support incident investigation.

18. Software Maintenance and Updates

Security risks and technology change over time. VendorVault may regularly update:

  • application code;
  • libraries;
  • dependencies;
  • infrastructure;
  • integrations;
  • authentication systems; and
  • security controls.

Updates may be made to address vulnerabilities, improve security, maintain compatibility or improve the reliability of the Service.

19. Security Reviews

VendorVault's security practices may be reviewed and updated as the platform grows and its functionality changes. Reviews may consider areas such as:

  • access controls;
  • authentication;
  • infrastructure;
  • data handling;
  • permissions;
  • third-party providers;
  • integration security;
  • account security;
  • software dependencies;
  • backups;
  • monitoring; and
  • incident response.

Security is treated as an ongoing operational responsibility rather than a one-time implementation.

20. Security Incidents

VendorVault maintains processes intended to help identify, investigate and respond to suspected security incidents. Depending on the circumstances, an incident response may include:

  • investigation;
  • restricting affected access;
  • securing accounts or systems;
  • addressing vulnerabilities;
  • working with relevant service providers;
  • restoring affected systems;
  • reviewing logs and technical information;
  • assessing affected information; and
  • implementing additional safeguards.

Where an incident involves personal information, we will assess our obligations under applicable privacy laws.

21. Data Breaches

If VendorVault becomes aware of a suspected data breach involving personal information, we will seek to assess and respond to the incident appropriately. Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will notify affected individuals and relevant authorities as required by law. Not every security incident constitutes an eligible data breach under Australian law.

22. Data Retention and Deletion

We aim to retain information only for as long as reasonably necessary for legitimate business, platform, contractual, security or legal purposes. Where personal information is no longer required and applicable law requires its destruction or de-identification, we will take reasonable steps to address that information appropriately. Data may sometimes remain temporarily within secure backups until the relevant backup is deleted, overwritten or otherwise taken out of active use. Further information is available in our Privacy Policy.

23. Account Closure

When an account is closed, information may not necessarily be deleted immediately. Some information may need to be retained for:

  • legal obligations;
  • regulatory obligations;
  • legitimate business records;
  • dispute resolution;
  • security investigations;
  • fraud prevention; or
  • other lawful purposes.

Information associated with an agency or shared property Vault may also continue to be retained where other authorised users or the relevant organisation require access.

24. User Responsibilities

Security is a shared responsibility. VendorVault users should:

  • use strong and unique passwords;
  • protect their login credentials;
  • secure their devices;
  • keep browsers and operating systems up to date;
  • avoid sharing accounts;
  • review access permissions regularly;
  • remove access when it is no longer required;
  • confirm that information is being shared with the correct person;
  • avoid uploading information that is unnecessary for the workflow; and
  • promptly report suspected security issues.

Users should exercise particular care when handling identity, compliance, buyer or other sensitive information.

25. Agency Responsibilities

Where VendorVault is used by a real estate agency, the agency remains responsible for managing its internal security and privacy obligations. This may include:

  • determining which employees require access;
  • removing access when staff leave or change roles;
  • managing client information appropriately;
  • complying with agency policies;
  • complying with legal and regulatory requirements; and
  • maintaining appropriate internal security practices.

VendorVault provides tools to support secure workflows but does not replace an agency's own governance and security responsibilities.

26. Responsible Data Collection

Collecting unnecessary information can increase privacy and security risk. Users should only upload or enter information reasonably required for a legitimate property, client, compliance or business purpose. VendorVault may modify its functionality over time to reduce unnecessary collection or restrict information where appropriate.

27. Privacy by Design

Where practical, VendorVault aims to consider privacy and security when designing new functionality. This may include consideration of:

  • what information is required;
  • who needs access;
  • how information should be shared;
  • whether access should be restricted;
  • how long information is required;
  • what third-party services are involved; and
  • the potential consequences of unauthorised access.

28. Service Availability

VendorVault aims to provide a reliable service but cannot guarantee uninterrupted availability. Service interruptions may occur because of:

  • maintenance;
  • infrastructure issues;
  • third-party outages;
  • software errors;
  • security incidents;
  • internet disruptions; or
  • circumstances outside our reasonable control.

Where practical, we aim to restore affected functionality as soon as reasonably possible.

29. Security Certifications

VendorVault does not claim to hold a particular security certification, accreditation or independent audit unless that certification is expressly identified by VendorVault as current. The absence of a particular certification does not mean security controls are not used. As VendorVault grows, we may consider additional security standards, independent assessments or certifications where appropriate.

30. No Absolute Security Guarantee

Although VendorVault takes security seriously, no software system, cloud platform, network or internet transmission can be made completely secure. Accordingly, we cannot guarantee that a cyberattack, system failure, human error or other security incident will never occur. Our commitment is to take reasonable measures appropriate to the platform, continually assess security risks and respond appropriately when issues are identified.

31. Reporting a Security Concern

If you believe you have identified:

  • a security vulnerability;
  • unauthorised access;
  • suspicious account activity;
  • accidental disclosure;
  • a privacy issue; or
  • another potential security concern, please contact us as soon as possible.

Email: connect@vendorvault.com.au Please include enough information for us to understand and investigate the issue. We ask that security researchers and users act responsibly and do not:

  • access information belonging to other users beyond what is necessary to demonstrate an issue;
  • alter or destroy data;
  • disrupt the Service;
  • use a vulnerability for personal gain; or
  • publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and address it.

We appreciate responsible reports that help us improve VendorVault.

32. Continuous Improvement

VendorVault is an evolving platform. Our infrastructure, security controls and operational procedures may change as:

  • new functionality is introduced;
  • risks change;
  • technology changes;
  • third-party providers change;
  • legal requirements develop; and
  • VendorVault grows.

We intend to continue reviewing our security practices and strengthening the platform where appropriate.

33. Contact

For security, privacy or data protection questions, please contact:

VendorVault

Operated by Portfolioapp Pty Ltd Email: connect@vendorvault.com.au Website: vendorvault.com.au For information about how we collect and handle personal information, please also review our Privacy Policy. For the contractual terms governing use of VendorVault, please review our Terms of Service.

VendorVault

Complete transparency before your property launches.

Legal Terms Privacy Customer Support Trust & Security
Contact Email VendorVault Back to home