The Ivory Index

Imperial Eminence Cyberguard Corporation · The Ivory Index

Vendor Management Policy

Tier V — Security Program · Ref: IECC-T5-004 · Version 1.0 · Effective 14 June 2026
IECC
Document: IECC-T5-004 Version: 1.0 Effective: 14 June 2026 Governing Law: Cayman Islands Intended Jurisdiction: Cayman Islands (upon incorporation)

Article I — Purpose

This Vendor Management Policy ("Policy") governs how IECC selects, onboards, reviews, and offboards third-party vendors and service providers. It ensures that vendors meeting IECC's security, legal, and operational standards are engaged, and that vendor relationships do not introduce unacceptable risk to IECC or its Customers.

Article II — Vendor Categories

CategoryDefinitionExamplesReview Level
CriticalProcesses Customer personal data or has access to production systemsCloud infrastructure, email/support platformFull due diligence + DPA + annual review
SignificantIntegrated into product delivery but no direct Customer data accessBuild tools, CDN, font deliverySecurity assessment + contractual terms + annual review
StandardBusiness operations; no Customer data accessAccounting software, project managementStandard vetting + terms review
Low-riskMinimal integration; public services onlyPublic APIs used for non-sensitive dataLightweight review

Article III — Vendor Selection

Before engaging any Critical or Significant vendor, IECC shall:

Article IV — Vendor Onboarding

Article V — Ongoing Vendor Review

Vendor CategoryReview FrequencyReview Scope
CriticalAnnualSecurity posture, certifications, incidents, DPA compliance, access review
SignificantAnnualSecurity posture, contract terms, access review
StandardBiennialTerms review, continued business need
Low-riskAd hoc (on material change)Continued suitability

Triggers for immediate out-of-cycle review: vendor data breach; material change in vendor ownership, control, or jurisdiction; regulatory action against vendor; significant change in vendor terms or security posture.

Article VI — Vendor Offboarding

Article VII — Vendor Incidents

Where a vendor notifies IECC of a security incident affecting IECC or Customer data, IECC will: (i) immediately assess the impact; (ii) invoke the Incident Response Policy (IECC-T4-003); (iii) notify affected Customers in accordance with legal obligations; and (iv) review whether to continue the vendor relationship.

Article VIII — Contact

Vendor management enquiries: legal@imperialecc.com.

Drafted with the assistance of
Voidlex
Imperial Legal Intelligence · IECC Suite · v2.6
This document was prepared with the assistance of Voidlex, a legal document drafting tool developed by Imperial Eminence Cyberguard Corporation (IECC). Voidlex is a drafting aid only. It does not constitute legal advice, does not practice law, and does not guarantee the legal enforceability of this document in any jurisdiction. Users are strongly encouraged to seek independent legal counsel before relying on this document for commercial, regulatory, or enforcement purposes.
Governing Law — All Disputes Cayman Islands · Grand Court of the Cayman Islands
IECC Registered Operations Planned Cayman Islands registration · pre-incorporation stage
Drafting System Voidlex v2.6 · Imperial Eminence Cyberguard Corporation
TRIBUNEH
TRIBUNEH · IECC Legal Division