AI Security ResearchIndependent public-source research

Site information

Privacy Notice

This notice describes the limited personal information used to provide invitation-only access, operate the research evaluation, collect feedback, and protect the site.

Effective July 25, 2026

Who operates this site

This site is operated by VendorSignal LLC.

Information the site handles

  • Invitation and membership data: email address, optional display name, access role and status, who invited the member, and invitation or sign-in timestamps. An administrator may provide this information before the invited person visits.
  • Sign-in and security data: one-time-code challenge records, hashed codes and session tokens, session and expiration timestamps, and hashed rate-limit identifiers derived from an email address or network address. Hosting and security providers may also process request and security-log data.
  • Evaluation activity: evaluation-session identifiers, application and research-corpus versions, and session start, last-seen, and end times.
  • Feedback: ratings, free-text comments, friction notes, page context, follow-up preference, and administrator triage fields. Feedback is associated with the invited member who submitted it.
  • Device-local progress: the research checklist can store completion state in the browser. That state remains on the device unless the browser clears it.

How the information is used

The information is used to confirm invitations, provide and secure access, prevent abuse, maintain evaluation sessions, understand whether the research is useful, respond to feedback, administer the pilot, troubleshoot problems, and maintain the reliability and security of the service.

The site does not use personal information for targeted advertising or sell it. If those practices change, this notice must be updated before the change takes effect.

Cookies and local storage

The site sets a necessary authentication cookie after a successful sign-in. The cookie contains a random session value; the stored server record contains its hash. The cookie is used to keep the member signed in and is not used for advertising. Hosting and security services may use additional strictly necessary security storage. The research checklist uses optional browser local storage.

Service providers and sharing

OpenAI Sites and Cloudflare provide application hosting, edge delivery, database, and security functions. Plunk processes the destination email address and one-time code to deliver sign-in messages. When feedback is stored, Plunk also delivers an administrative notification containing the feedback record identifier, checkpoint, and application surface. That notification excludes the member identity, ratings, comments, and friction notes. These providers process information as needed to perform their services. Information may also be disclosed when required by law, to protect the service or its users, or as part of a properly managed business transfer.

Following an external source link takes the visitor to another organization's site, which has its own privacy practices.

Retention

  • One-time codes expire after 10 minutes. Authentication sessions expire after no more than 30 days and after 7 days without activity.
  • Expired challenges, sessions, and rate-limit records are removed through administrator-run cleanup; removal is not currently automatic.
  • Feedback and unreferenced evaluation records become eligible for administrator-run cleanup after 90 days.
  • Invitation and membership records are not included in the 90-day cleanup and are maintained separately for access administration.
  • Provider logs and backups may follow provider-specific retention schedules.

Security and international processing

The site uses access controls, hashed authentication secrets, request limits, and other safeguards intended to protect the information it handles. No online service can guarantee absolute security. Service providers may process information in locations where they operate.

Your choices and requests

You may ask about, correct, or request deletion of personal information associated with you. The operator may need to verify the requester's identity and will handle requests as required by applicable law. You can decline to submit optional feedback or request follow-up. Do not put client, incident, credential, contract, deployment, or other confidential information in feedback.

Children

This invitation-only business research site is not directed to children under 13, and children should not submit personal information to it.

Privacy and correction contact

Email info@vendorsignal.io for a privacy request, factual correction, or rights-holder concern.