About VendorDeck
We build the security page that small software companies need to get through enterprise procurement, without first spending five figures on an audit.
The problem we work on
A startup's first enterprise deal usually stalls in the same place: the security questionnaire. A spreadsheet arrives with somewhere between forty and three hundred questions, most of which assume a security programme the vendor has not built yet. The deal slows by weeks. Some of them never restart.
The standard advice is to get SOC 2. That is reasonable advice for a company with revenue to protect and months to spare, and bad advice for one trying to close the deal that would fund it. SOC 2 typically costs £15,000–£30,000 and takes three to twelve months. The questionnaire is due on Friday.
What we do instead
VendorDeck is built on MVSP, the Minimum Viable Secure Product baseline, maintained by a working group with contributors from Google, Salesforce, Okta, Slack, Netflix and CISA. It is 25 controls describing what a B2B software vendor should have in place — the whole standard, not a subset of it.
You answer the checklist, and VendorDeck produces:
- a hosted Trust Centre at a shareable URL, so one link replaces the spreadsheet;
- security policies generated from your answers and your company details;
- lead capture, so you know which prospects are reviewing your security documentation and when;
- a machine-readable security profile API that AI procurement agents can read without scraping the page.
What we are careful about
MVSP is self-attested. There is no auditor, and VendorDeck does not verify your answers — we say so on every Trust Centre and in the API response. Publishing a compliance score you have not earned would fail the first buyer who looked closely, which helps nobody.
We are equally direct about the ceiling. Regulated buyers will still require SOC 2 Type II or ISO 27001, and MVSP will not change that. What it does is get you through the earlier filters, and give you a clear picture of which controls you are actually missing.
Who it is for
UK startups, agencies and consultancies selling software or services to larger organisations — typically pre-Series A, without a dedicated security hire, facing their first serious procurement review.