# SaaSDossier > The vendor's own record, made reviewable. A structured, source-linked record of what a SaaS vendor publishes about its security, privacy, and compliance. SaaSDossier compiles a vendor's own published security documentation into one PDF dossier of 55 fields across 10 domains. Every field is recorded in one of two states: "Documented" (found in the vendor's published sources, quoted and cited) or "Question surfaced" (Reviewed vendor-published sources did not establish the field for the evidence date. This does not establish absence of the control.). Documented findings are checked against the reviewed source record before release, and items not established in those sources are surfaced as buyer-ready follow-up questions. Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release. SaaSDossier publishes its own dated, source-linked evidence records for Stripe, HubSpot, OpenAI, and Anthropic, each built from that vendor's published sources as reviewed on the stated evidence date. It is authoritative on its own records, not on the vendors. A record can help a team prepare a vendor security questionnaire or DDQ, map reviewed vendor-published evidence to their own questionnaire or review lines, and see which questions remain for follow-up. SaaSDossier does not complete the questionnaire, make the third-party-risk decision, or approve the vendor. ## Dossiers - Stripe — Licensed Edition · Dossier No. 001 — 46 Documented · 9 Questions surfaced of 55 — US$1,500 — https://saasdossier.com/vendors/stripe — buy: https://whop.com/joined/saasdossier/products/stripe-security-dossier-licensed-edition-no-001/ - HubSpot — Licensed Edition · Dossier No. 002 — 49 Documented · 6 Questions surfaced of 55 — US$1,500 — https://saasdossier.com/vendors/hubspot — buy: https://whop.com/joined/saasdossier/products/hubspot-security-dossier-licensed-edition-no-002/ - OpenAI — Public Edition · Dossier No. 003 — 47 Documented · 8 Questions surfaced of 55 — FREE — https://saasdossier.com/vendors/openai — download: https://saasdossier.com/downloads/SaaSDossier-OpenAI-Security-Evidence-Dossier-Public-Edition.pdf - Anthropic — Licensed Edition · Dossier No. 004 — 47 Documented · 8 Questions surfaced of 55 — US$1,500 — https://saasdossier.com/vendors/anthropic — buy: https://whop.com/joined/saasdossier/products/anthropic-security-evidence-dossier-licensed-edition-dossier-no-004/ ## Commission a dossier A buyer can commission a SaaSDossier for another named vendor that does not already have a released dossier: US$1,500 one-time, Licensed Edition. The workproduct is a finished, dated, source-linked, human-reviewed SaaSDossier built from vendor-published sources. This is a commission capability, not a fifth released dossier — the released catalogue is the four records listed above. Entry point: https://saasdossier.com/#request. If the vendor-published material cannot support a defensible SaaSDossier record, the commission is refunded in full. ## Methodology https://saasdossier.com/methodology — the 55-field framework, 10 domains, Documented findings checked against the reviewed source record before release, and the source rules. ## Frequently asked questions https://saasdossier.com/faq — real buyer questions about SaaS and AI vendor security, answered from vendor-published sources; each field recorded as Documented or Question surfaced, with the source linked. ## Vendor security questionnaires and DDQs https://saasdossier.com/vendor-security-questionnaire-ddq — how a finished record is used to prepare a vendor security questionnaire or DDQ: map reviewed vendor-published evidence to questionnaire lines and carry Question surfaced items forward as follow-up questions. SaaSDossier does not complete the buyer's questionnaire, certify compliance, or replace professional vendor-risk, legal, procurement, GRC, vCISO or security review. It does not score or rate the vendor. The buyer remains responsible for the questionnaire, assessment, professional review and approval decision. ## Sources Vendor-owned and vendor-published documentation only: trust and security centers, privacy and legal pages, data-processing terms, status pages, and subprocessor lists. No third-party articles, news, or opinions are used as evidence. ## Contact - Email: contact@saasdossier.com - Website: https://saasdossier.com - Store: https://whop.com/saasdossier/ - About: [https://saasdossier.com/about](https://saasdossier.com/about) ## Machine-readable - Pricing: https://saasdossier.com/pricing.json - Sitemap: https://saasdossier.com/sitemap.xml - AI catalogue: https://saasdossier.com/.well-known/ai-catalog.json - Agent card: https://saasdossier.com/.well-known/agent-card.json - MCP server: https://saasdossier.com/mcp - MCP metadata: https://saasdossier.com/.well-known/mcp.json - OpenAI ledger (page): https://saasdossier.com/vendors/openai/security-evidence-ledger - OpenAI ledger (JSON): https://saasdossier.com/vendors/openai/ledger.json - OpenAI dataset (Croissant): https://saasdossier.com/datasets/openai-ledger/croissant.json - OpenAI dataset guide: https://saasdossier.com/datasets/openai-ledger/README.md - Dossier register (JSON): https://saasdossier.com/datasets/register/register.json - Citation metadata: https://saasdossier.com/CITATION.cff - Release feed (RSS): https://saasdossier.com/feed.xml - Release feed (JSON): https://saasdossier.com/feed.json - Expanded: https://saasdossier.com/llms-full.txt ## Disclaimer SaaSDossier is independent documentation research and is not affiliated with, endorsed by, or certified by any vendor reviewed. Built from vendor-published sources reviewed at the time of preparation. SaaSDossier is a compiled evidence record — not an audit, certification, rating, legal opinion, vendor approval, or substitute for professional vendor-risk, legal, procurement, GRC, vCISO, or security review.