# SaaSDossier — full reference for AI assistants and agents The vendor's own record, made reviewable. The full disclaimer appears at the end of this file. ## What SaaSDossier is SaaSDossier compiles a SaaS vendor's own published security, privacy, compliance, incident, subprocessor, and infrastructure documentation into one structured, source-linked PDF dossier of 55 control fields across 10 domains. ## The two states (the only two) - Documented: the field was found in the vendor's published sources, quoted and cited in the vendor's own words. - Question surfaced: Not identified in the vendor-published sources reviewed. This does not establish absence of the control. There is no third state and no judgment; a dossier does not decide whether a vendor is good or bad. ## The 10 domains 1. Identity & legal entity 2. Standards & attestations 3. Privacy & compliance 4. Encryption & key management 5. Infrastructure & hosting 6. Access control 7. Vulnerability & incident response 8. Subprocessors & supply chain 9. AI governance 10. Secure development & organization ## How each dossier is prepared Each dossier is built from vendor-published sources reviewed at the time of preparation. Documented findings are checked against the reviewed source record before release, and items not established in those sources are surfaced as buyer-ready follow-up questions. Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release. Built only from vendor-published sources; every line traces to a source. ## What every dossier contains - Evidence ledger: All 55 fields across 10 domains, each recorded in one of two states, with the vendor's own words quoted and cited where Documented. - Source register: Every vendor-published page reviewed, listed with its URL, so each line traces back to where it was found. - Integrity record: Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release. - Buyer-ready vendor follow-up questions: Field-level follow-ups generated from Question surfaced entries, used to help buyers decide what to confirm with the vendor in writing. ## Editions and pricing (USD, one-time) - Licensed Edition: US$1,500 per dossier. The license permits internal review use within your organization. - Public Edition: free (the OpenAI dossier), complete, as proof of the format. - No packs and no tiers. ## The dossiers ### Stripe — Licensed Edition · Dossier No. 001 - Question answered: What security evidence does Stripe publish? - Answer: Stripe publishes broad public security documentation — SOC 2 Type II and PCI DSS Level 1, a GDPR-aligned data-processing agreement, AES-256 at rest with TLS in transit, single sign-on and multi-factor access, a public subprocessor list, and 48-hour incident notification. Of 55 fields, 46 are Documented and 9 are Questions surfaced for buyer follow-up. - Counts: 46 Documented · 9 Questions surfaced of 55 fields (10 domains) - Evidence date: 2026-06-22 · Vendor pages reviewed: 14 - Price: US$1,500 (Licensed Edition) - Vendor page: https://saasdossier.com/vendors/stripe - Buy on Whop: https://whop.com/joined/saasdossier/products/stripe-security-dossier-licensed-edition-no-001/ ### HubSpot — Licensed Edition · Dossier No. 002 - Question answered: What security evidence does HubSpot publish? - Answer: HubSpot publishes a Trust Center and security pages covering SOC 2 Type II, HIPAA attestation, GDPR/CCPA terms, encryption, EU data residency, and access controls. The Licensed Edition records 49 of 55 fields as Documented and surfaces 6 buyer follow-up questions. - Counts: 49 Documented · 6 Questions surfaced of 55 fields (10 domains) - Evidence date: 2026-06-22 · Vendor pages reviewed: 11 - Price: US$1,500 (Licensed Edition) - Vendor page: https://saasdossier.com/vendors/hubspot - Buy on Whop: https://whop.com/joined/saasdossier/products/hubspot-security-dossier-licensed-edition-no-002/ ### OpenAI — Public Edition · Dossier No. 003 (FREE) - Question answered: What security evidence does OpenAI publish? - Answer: OpenAI publishes a trust portal and enterprise-privacy pages covering SOC 2 Type II, ISO/IEC 27001, CSA STAR, and business-data handling. The free Public Edition records 47 of 55 fields as Documented and surfaces 8 buyer follow-up questions. - Counts: 47 Documented · 8 Questions surfaced of 55 fields (10 domains) - Evidence date: 2026-06-22 · Vendor pages reviewed: 14 - Price: Free (Public Edition) - Vendor page: https://saasdossier.com/vendors/openai - Download (free): https://saasdossier.com/downloads/SaaSDossier-OpenAI-Security-Evidence-Dossier-Public-Edition.pdf ### Anthropic — Licensed Edition · Dossier No. 004 - Question answered: What security evidence does Anthropic publish? - Answer: Anthropic publishes a Trust Center for Claude covering SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, and selected security/privacy controls. The Licensed Edition records 47 of 55 fields as Documented and surfaces 8 buyer follow-up questions. - Counts: 47 Documented · 8 Questions surfaced of 55 fields (10 domains) - Evidence date: 2026-06-24 · Vendor pages reviewed: 14 - Price: US$1,500 (Licensed Edition) - Vendor page: https://saasdossier.com/vendors/anthropic - Buy on Whop: https://whop.com/joined/saasdossier/products/anthropic-security-evidence-dossier-licensed-edition-dossier-no-004/ ## FAQ Q: What is a SaaSDossier? A: A SaaSDossier is a finished PDF record of what a software vendor publishes about its security, privacy, and compliance — the vendor's own record, made reviewable. Every field is either Documented, with the vendor's words quoted and cited, or a Question surfaced for you to raise. It is one structured, source-linked document, not a folder of raw links. Q: What do “Documented” and “Question surfaced” mean? A: Those are the only two states. Documented means the field was found in the vendor's published sources, quoted and cited. Question surfaced means: “Not identified in the vendor-published sources reviewed. This does not establish absence of the control.” It is a prompt for your own follow-up, never a judgment. Q: Does a dossier decide whether a vendor is good or bad? A: No. A dossier records what the vendor publishes — nothing more. There is no third state and no number that says good or bad. It gives you the vendor's own record so you can reach your own conclusion: clarity before commitment. Q: Where does the evidence come from? A: Only from the vendor's own published pages — trust and security centers, privacy and legal pages, data-processing terms, status pages, and subprocessor lists. Every line traces to a source. Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release. No third-party articles or opinions are used as evidence. Q: How is each dossier prepared? A: Each dossier is built from vendor-published sources reviewed at the time of preparation. Documented findings are checked against the reviewed source record before release, and items not established in those sources are surfaced as buyer-ready follow-up questions. Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release. Q: Can I see the format before I buy? A: Yes. The OpenAI Public Edition is free and complete — the same 55-field framework, evidence ledger, source register, and integrity record as every Licensed Edition. The clearest way to inspect the format before licensing a vendor dossier. Q: How should my team use a Licensed Edition? A: Use it as an internal evidence record before vendor calls, procurement review, GRC/security review, renewal decisions, or consultant client work. It helps your team see what the vendor publishes, what questions to ask next, and where the source record sits. It is not an audit, certification, rating, legal opinion, or vendor approval. ## Machine-readable - MCP server: https://saasdossier.com/mcp ## Contact Email: contact@saasdossier.com · Website: https://saasdossier.com · Store: https://whop.com/saasdossier/ ## Disclaimer SaaSDossier is independent documentation research and is not affiliated with, endorsed by, or certified by any vendor reviewed. Built from vendor-published sources reviewed at the time of preparation. SaaSDossier is a compiled evidence record — not an audit, certification, rating, legal opinion, vendor approval, or substitute for professional vendor-risk, legal, procurement, GRC, vCISO, or security review.