Secure by design. Built for trust.

Supplier Digital Solutions (SDS) is committed to protecting the confidentiality, integrity, and availability of the information entrusted to our platform.

As a global supplier information platform, SDS is designed to support organizations across industries, geographies, and regulatory environments through practical risk management, responsible data stewardship, and continuous improvement.

Our security approach
Security is incorporated into technology, operations, and governance across the SDS platform.

Protect Information

Safeguards designed to help prevent unauthorized access, disclosure, alteration, or loss.

Manage Access

Access based on appropriate authorization and business need.

Monitor and Respond

Established processes for security monitoring, investigation, response, and recovery.

Practical principles that guide the SDS security program.

Protect Information
SDS implements technical and administrative safeguards designed to help protect buyer, supplier, and platform information.
Minimize Access
Access is granted based on business need, appropriate authorization, and least-privilege principles.
Monitor and Respond
Security events are monitored and investigated through established operational processes.
Secure Development
Security considerations are incorporated into design, development, testing, deployment, and maintenance activities.
Continuously Improve
SDS regularly reviews risk, evaluates controls, and evolves security practices as the platform grows.

Security across the platform lifecycle.

Our security program addresses the operational and technical areas required to support a trusted global platform.
Access Management
Role-based access controls and account lifecycle processes help ensure appropriate access to information and platform capabilities.
Data Protection
Technical and administrative measures support the protection of information throughout storage, transmission, and authorized sharing.
Application Security
Security practices are incorporated into platform development, testing, deployment, and ongoing maintenance activities.
Infrastructure Security
Modern infrastructure and cloud technologies support platform resilience, operational security, and service availability.
Incident Response
Established procedures support identification, escalation, investigation, containment, recovery, and post-incident review.
Business Continuity
Continuity and recovery planning activities help support service resilience and restoration of critical operations.

Security works best when every participant plays a role.

SDS Responsibilities
  • Secure platform operations
  • Access management processes
  • Infrastructure and application security
  • Security monitoring and incident response
  • Privacy and data protection controls
Buyer Responsibilities
  • Manage authorized users and access
  • Review supplier information appropriately
  • Maintain internal procurement and governance controls
  • Use information in accordance with applicable requirements
Supplier Responsibilities
  • Maintain accurate business information
  • Protect account credentials
  • Manage authorized users
  • Review information shared with participating buyers

Responsible Disclosure

SDS welcomes responsible disclosure of suspected security vulnerabilities. Reports are reviewed and investigated through the designated SDS security process.

One place for enterprise trust information.

Customers and partners can review public trust resources and request additional documentation where appropriate.

Continuous improvement as SDS grows.

SDS intends to continue maturing its security and assurance programs through ongoing investment in governance, risk management, operational controls, resilience, and independent review activities. Certifications and attestations will only be described as complete after the applicable review has been successfully finalized and remains current.