Vendor review

Security and legal review materials for Whiteboxx.

A single place for procurement, security, privacy, and legal teams to request the documents and reports they need before an order, SOW, or renewal.

ISO 27001:2022
Certificate active
September 2026 scans
0 critical, high, medium, or low findings reported
Evidence room
Magic-link access for approved domains

Upfront status

Enough to orient the review, with the detailed packet gated.

ISO 27001:2022 certified Certificate no. 54A81E23, issued September 29, 2026.
Recent security scans available Public and beta reports dated September 24, 2026.
Contract and data documents ready DPA, subprocessors, support, acceptable use, and MSA materials are in the evidence room.

Evidence packet

One organized room for the materials buyers usually ask for.

The evidence room is arranged around the review jobs enterprise teams normally split across security, privacy, legal, procurement, and business owners.

01

Security certification

ISO 27001:2022 certificate, scope, dates, and related security summaries.

02

Security reports

Recent public and beta scan reports for security-review intake.

03

Data protection

DPA, data handling boundaries, subprocessors, and privacy-policy references.

04

Commercial documents

MSA, SOW/Sales Order support, service policies, and acceptable-use terms.

Data handling

Clear boundaries for customer data and business records.

Whiteboxx materials describe how customer data, outputs, account identity, operational logs, and security records are handled. Full terms remain tied to the applicable MSA, Sales Order, SOW, DPA, and written customer instructions.

Review boundaries

  • Customer-owned data and outputs remain bounded by agreement.
  • Human review is expected for consequential or regulated decisions.
  • Security and privacy artifacts are versioned and access logged.
  • Sensitive or regulated data requires written terms before use.

Document set

Legal and operating materials, sorted for review.

The public page confirms what is available. The evidence room holds the downloadable documents and reports for approved reviewers.

Data Processing Addendum

Processing roles, customer instructions, security measures, and subprocessors.

Security and Privacy Exhibit

Controls, access practices, incident process, and review responsibilities.

Subprocessor List

Third-party services used to operate Whiteboxx services.

Support and Service Policy

Support channels, target response handling, and maintenance expectations.

Acceptable Use and Data Policy

Use restrictions, sensitive-data boundaries, and output responsibilities.

Master Services Agreement

SOW and Sales Order model for professional services and hosted software services.

Review responsibilities

Operating expectations without inflated claims.

Whiteboxx materials are prepared for business review and contract alignment. Customer teams should review outputs before legal, financial, employment, healthcare, or similarly consequential use.

Customer review Consequential use should stay subject to qualified business review.
Documented evidence Diligence artifacts distinguish documents, reports, and assumptions.
Contract controls Customer-specific terms belong in SOWs, Sales Orders, or addenda.